and-pick
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is defined as a read-only recommendation engine with boundaries that explicitly prohibit state mutation such as task assignments, comments, or repository modifications.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes untrusted data from project repositories. Ingestion points: Processes
.and/config.yml, backend records (issues/PRDs), comments, and attachments like logs or recordings in SKILL.md. Boundary markers: No specific delimiters or safety warnings for external content are defined. Capability inventory: Limited to read-only analysis and markdown output; no execution tools, subprocesses, or network exfiltration operations are present. Sanitization: No validation or sanitization steps are specified for the external data ingested.
Audit Metadata