issue-intake
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a controlled process for ingesting external signals without performing autonomous triage or execution.
- [SAFE]: The skill ingests untrusted data from users and external PRs, creating a surface for indirect prompt injection. 1. Ingestion: The skill reads repository configuration (.and/config.yml), user signals, and external PR descriptions/diffs. 2. Boundaries: Clear instructions exist to separate author claims from verified facts and to preserve raw context without settling decisions. 3. Capabilities: Limited to reading configuration and creating/updating records via the ai-native-backend-contract tool. 4. Sanitization: Context is preserved verbatim, placing the responsibility for safety and triage on subsequent workflow steps.
Audit Metadata