and-pack
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a structured framework for managing development tasks, including implementation decisions, testing plans, and deployment constraints. No malicious patterns, obfuscated code, or unauthorized behaviors were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external content from GitHub work records and comments, which represents a potential ingestion surface for indirect prompt injection. This behavior is consistent with the skill's primary purpose. 1. Ingestion points: The skill reads work bodies and comments from GitHub as described in the Process section of SKILL.md. 2. Boundary markers: No explicit delimiters or instructions to ignore embedded instructions are provided in the instructions. 3. Capability inventory: The skill has the capability to publish packages and write state changes to GitHub repositories via the and-workflow-contract toolset. 4. Sanitization: No explicit sanitization of ingested comment content is mentioned in the skill instructions.
Audit Metadata