triage
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via external tracker data.\n
- Ingestion points: The skill reads issue bodies and comments from GitHub or Linear trackers via the
Readtool (SKILL.md).\n - Boundary markers: There are no defined delimiters or instructions to ignore potentially malicious commands embedded within the fetched issue content.\n
- Capability inventory: Allowed tools include
Bash,Write, andEdit, which could allow an agent to execute shell commands or modify the repository based on malicious instructions found in untrusted issue data (SKILL.md).\n - Sanitization: No input validation or sanitization process is defined for the external data ingested during the triage process.
Audit Metadata