skills/andiedie/skills/and-sweep/Gen Agent Trust Hub

and-sweep

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted data from GitHub work records, delivery units, and handoff evidence.\n
  • Ingestion points: Read Work Record, Read Delivery Unit, and Read Deployment Handoff as defined in SKILL.md.\n
  • Boundary markers: The instructions do not define specific delimiters to isolate external data from the agent's internal logic.\n
  • Capability inventory: The skill has the ability to read and mutate GitHub repository state (mutations require approval).\n
  • Sanitization: No explicit sanitization or validation rules are provided for the content read from external records.\n- [SAFE]: The skill includes a 'Repair' classification that mandates explicit human approval for any mutation that alters workflow meaning or authority, providing a critical safety checkpoint.\n- [SAFE]: The skill configuration explicitly disables model invocation (disable-model-invocation: true) and implicit invocation, adhering to the principle of least privilege.\n- [SAFE]: No obfuscation, hardcoded credentials, or unauthorized network operations were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 06:02 AM
Security Audit — agent-trust-hub — and-sweep