and-pick
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data from GitHub repositories, which represents an attack surface for indirect prompt injection.
- Ingestion points: GitHub issue descriptions, PRD packages, and linked evidence or attachments processed via
Read Delivery Unit. - Boundary markers: Absent; no delimiters or explicit instructions to ignore embedded commands are defined for the ingested data.
- Capability inventory: Read-only workflow; the skill identifies work units for recommendation but does not have file-write or network-operation capabilities.
- Sanitization: Absent; no validation or escaping of external content is specified.
- [NO_CODE]: The skill consists entirely of markdown-based process instructions and configuration metadata without any accompanying executable scripts.
Audit Metadata