intake
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from a raw signal to create GitHub issues without sufficient safety boundaries. Ingestion points: The raw signal mentioned in SKILL.md. Boundary markers: No markers or explicit instructions are provided to delimit the input data from the agent's internal instructions. Capability inventory: The skill utilizes the capability to write content to an external platform by creating GitHub issues. Sanitization: There is no evidence of input validation, escaping, or sanitization described in the instructions.
Audit Metadata