rfc
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
codeCLI tool to open the generated RFC in a new VS Code window. * Evidence:code --new-window "<absolute-path>"in Phase 7 of SKILL.md. - [EXTERNAL_DOWNLOADS]: The skill retrieves context from user-provided GitHub and Linear URLs. * Evidence: Supported inputs include GitHub PR/issue URLs and Linear tickets in the 'Resolve the input' section.
- [PROMPT_INJECTION]: The skill lacks sanitization for data ingested from repository files and external URLs, creating a surface for indirect prompt injection. * Ingestion points: Repository code scanning and URL resolution in Phase 1 of SKILL.md. * Boundary markers: None present to distinguish external data from internal instructions. * Capability inventory: The skill can write to the filesystem and execute local shell commands. * Sanitization: No input validation or escaping logic is defined for processed content.
Audit Metadata