implement
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from specifications or tickets and utilizes powerful capabilities, creating a surface for indirect prompt injection attacks.
- Ingestion points: Instructions in
SKILL.mddirect the agent to implement work based on a "spec or set of tickets" provided in the session context. - Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings to help the agent distinguish between the specification data and the skill's operational instructions.
- Capability inventory: The skill allows the use of
Bash,Write, andEdittools, enabling the agent to modify the file system and execute shell commands based on potentially malicious content in the tickets. - Sanitization: There is no mention of sanitizing, escaping, or validating the content of the external specifications before they are acted upon.
Audit Metadata