flow-brief

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data sources which could contain malicious instructions.
  • Ingestion points: The agent is instructed to read ticket.md, project instructions, and various file attachments as the primary source for generating briefs.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between data to be summarized and potential instructions embedded within the source tickets.
  • Capability inventory: The agent has the capability to write to the local filesystem (specifically .task/<KEY>/brief.md) and invoke other tools/skills like flow-review or flow-journal to process the data.
  • Sanitization: No validation or sanitization steps are described for the input data before it is incorporated into the brief or passed to review tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:04 AM
Security Audit — agent-trust-hub — flow-brief