tiger-team-identifier

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for Indirect Prompt Injection.
  • Ingestion points: The skill is designed to read and analyze content from Slack channels, Jira/Linear tickets, GitHub PR descriptions, and code comments, all of which are untrusted external sources.
  • Boundary markers: There are no instructions provided to the agent to use delimiters or to ignore potential instructions embedded within the retrieved data.
  • Capability inventory: The agent has access to powerful tools, including Bash and MCP tools for GitHub, Slack, and PagerDuty, which could be exploited if an indirect injection successfully redirects the agent's behavior.
  • Sanitization: The instructions do not include any steps for sanitizing, validating, or escaping the data fetched from external platforms before it is analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 08:05 AM
Security Audit — agent-trust-hub — tiger-team-identifier