and-intake
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious code, obfuscation, persistence mechanisms, or unauthorized privilege escalations were detected. The skill is instructional and its behavior is consistent with its stated purpose.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from bug reports and external pull requests. 1. Ingestion points: raw user requests and pull request data (SKILL.md, external-pr-signals.md). 2. Boundary markers: The instructions explicitly require the agent to distinguish 'author claims' from 'Agent-confirmed facts', preventing the blind adoption of instructions inside intake data. 3. Capability inventory: The skill interacts with GitHub work records (read/write). 4. Sanitization: Logical separation of user-provided content from agent-generated analysis serves as a mitigation against embedded malicious instructions.
Audit Metadata