and-claim
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional text and configuration for managing workflow states. No executable code, remote downloads, or credential exposures were found. All referenced skills (e.g.,
and-workflow-contract,and-pack) appear to be part of the same vendor's toolset. - [PROMPT_INJECTION]: The skill uses natural instructional language and does not attempt to bypass safety filters or override agent behavior. The process involves reading external delivery units and GitHub issues, which creates a surface for potential indirect prompt injection. However, the skill focuses on status management and lacks high-privilege execution capabilities that would make such an attack impactful.
- Ingestion points: External delivery units and GitHub issues processed via the
Read Delivery Unitstep. - Boundary markers: None explicitly defined for differentiating untrusted external content from instructions.
- Capability inventory: Capabilities are limited to recording ownership status and appending receipt text to GitHub issues.
- Sanitization: No specific sanitization or filtering is defined for the content read from external delivery units.
Audit Metadata