finish
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could potentially influence its automated repository actions. * Ingestion points: The agent is instructed to use the 'Spec', 'ticket', and 'code-review' from the task context and conversation history. * Boundary markers: There are no instructions to use delimiters or ignore embedded commands within the ingested text. * Capability inventory: The skill utilizes capabilities to push branches, squash-merge code into the default branch, and remove file system worktrees. * Sanitization: No explicit validation or filtering of the external task data is defined before the agent executes potentially destructive or sensitive repository operations.
Audit Metadata