blog-post
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted external sources, such as GitHub PR descriptions, diffs, and web search results, to generate content. This creates a surface for indirect prompt injection where malicious instructions could be embedded in PR comments or search results to influence the agent's behavior.
- Ingestion points: Phase 1 reads input from marketing briefs,
gh pr view,gh pr diff, and codebase files. Phase 2 performs web research on external sites. - Boundary markers: The instructions do not define explicit boundary markers or delimiters to isolate untrusted input from system instructions.
- Capability inventory: The skill executes shell commands (
git,gh), performs network requests (web search), and writes files to the local filesystem. - Sanitization: No sanitization or validation mechanisms are specified for the external data before it is processed by the model.
- [COMMAND_EXECUTION]: The skill uses local CLI tools to gather context.
- Details: It executes
gh pr viewandgh pr diffto fetch Pull Request data, and usesgit diffandgit logto analyze code changes. - [EXTERNAL_DOWNLOADS]: The skill performs research using external network operations.
- Details: Phase 2 uses a web search capability to analyze competitor blog posts and market trends from arbitrary third-party websites.
Audit Metadata