swe-method

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown documentation and contains no scripts or executable content.
  • [PROMPT_INJECTION]: The skill defines a workflow for processing untrusted external data, creating an indirect prompt injection surface.
  • Ingestion points: Slack threads, Jira tickets, and meeting transcripts as mentioned in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present.
  • Capability inventory: The workflow involves codebase exploration, branch/PR inspection, and validation of APIs, databases, and CLI tools.
  • Sanitization: There are no instructions for sanitizing or escaping the data fetched from external systems.
  • [DATA_EXFILTRATION]: No network exfiltration or unauthorized sensitive file access was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 10:58 AM
Security Audit — agent-trust-hub — swe-method