twg-engineering-work

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill operates by retrieving and processing external, untrusted data, which presents a surface for indirect prompt injection.
  • Ingestion points: The skill reads pull request titles, descriptions, comments, and repository source code as specified in SKILL.md and references/code-search.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following instructions that might be embedded within the retrieved PR data or code comments.
  • Capability inventory: The skill uses the twg CLI to perform data retrieval, code search, and information hydration.
  • Sanitization: The instructions do not specify any validation or sanitization steps for the data fetched from external SCM or issue tracking platforms.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 07:04 AM
Security Audit — agent-trust-hub — twg-engineering-work