twg-engineering-work
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill operates by retrieving and processing external, untrusted data, which presents a surface for indirect prompt injection.
- Ingestion points: The skill reads pull request titles, descriptions, comments, and repository source code as specified in
SKILL.mdandreferences/code-search.md. - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following instructions that might be embedded within the retrieved PR data or code comments.
- Capability inventory: The skill uses the
twgCLI to perform data retrieval, code search, and information hydration. - Sanitization: The instructions do not specify any validation or sanitization steps for the data fetched from external SCM or issue tracking platforms.
Audit Metadata