and-triage
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from issue records and pull requests without sufficient safeguards. 1. Ingestion points: The skill reads titles, bodies, comments, and PR diffs from external work records. 2. Boundary markers: Absent; the instructions do not specify delimiters to isolate external content from the skill's logic. 3. Capability inventory: The agent is authorized to modify backend state and execute 'reproduction attempts'. 4. Sanitization: Absent; no validation or filtering of ingested content is mentioned.
- [COMMAND_EXECUTION]: The instruction to perform 'proportionate reproduction attempts' based on reporter-provided steps grants the agent the capability to execute commands derived from untrusted input, which could lead to unauthorized command execution if the input is malicious.
Audit Metadata