skills/andiedie/skills/and-pack/Gen Agent Trust Hub

and-pack

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external sources including issue comments, triage notes, and attachments during the "Load source of truth" phase in SKILL.md. This ingestion of external content without explicit boundary markers or sanitization logic represents an attack surface for indirect prompt injection, where malicious instructions embedded in the input data could potentially influence the agent's synthesis of the final package contract.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 02:31 AM
Security Audit — agent-trust-hub — and-pack