and-sweep
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted data from GitHub work records, delivery units, and handoff evidence.\n
- Ingestion points:
Read Work Record,Read Delivery Unit, andRead Deployment Handoffas defined inSKILL.md.\n - Boundary markers: The instructions do not define specific delimiters to isolate external data from the agent's internal logic.\n
- Capability inventory: The skill has the ability to read and mutate GitHub repository state (mutations require approval).\n
- Sanitization: No explicit sanitization or validation rules are provided for the content read from external records.\n- [SAFE]: The skill includes a 'Repair' classification that mandates explicit human approval for any mutation that alters workflow meaning or authority, providing a critical safety checkpoint.\n- [SAFE]: The skill configuration explicitly disables model invocation (
disable-model-invocation: true) and implicit invocation, adhering to the principle of least privilege.\n- [SAFE]: No obfuscation, hardcoded credentials, or unauthorized network operations were detected.
Audit Metadata