skills/andiedie/skills/and-triage/Gen Agent Trust Hub

and-triage

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it is designed to ingest and process untrusted external data. Ingestion points: The workflow requires reading GitHub issue bodies, pull request diffs, comments, and attachments to make triage decisions (SKILL.md). Boundary markers: The skill includes a 'Workflow Contract' and instructions to 'Keep author claims distinct from Agent-observed evidence,' which provides a logical boundary for the model to evaluate the reliability of external data. Capability inventory: The skill has the authority to mutate GitHub work records, change lifecycle outcomes, and update state reasons based on the ingested content. Sanitization: No explicit sanitization or filtering of the external text is mentioned, relying instead on the model's grounding instructions to maintain safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 06:02 AM
Security Audit — agent-trust-hub — and-triage