external-feedback-triage

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from external sources, creating a potential surface for indirect prompt injection.
  • Ingestion points: External technical feedback, scanner results, blog advice, and model suggestions identified in SKILL.md.
  • Boundary markers: The instructions require the agent to restate feedback in neutral technical terms and perform a triage loop to isolate the external claim from the current task context.
  • Capability inventory: No command execution, network requests, or file-writing tools are defined in either SKILL.md or references/review-feedback.md.
  • Sanitization: The skill mandates the use of an 'evidence-before-claims' verification step and cross-referencing suggestions against local configuration and evidence before acceptance.
  • [NO_CODE]: The skill consists purely of Markdown instructions and reference tables; no executable scripts or system commands are provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:20 PM
Security Audit — agent-trust-hub — external-feedback-triage