tiger-team-identifier
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for Indirect Prompt Injection.
- Ingestion points: The skill is designed to read and analyze content from Slack channels, Jira/Linear tickets, GitHub PR descriptions, and code comments, all of which are untrusted external sources.
- Boundary markers: There are no instructions provided to the agent to use delimiters or to ignore potential instructions embedded within the retrieved data.
- Capability inventory: The agent has access to powerful tools, including
Bashand MCP tools for GitHub, Slack, and PagerDuty, which could be exploited if an indirect injection successfully redirects the agent's behavior. - Sanitization: The instructions do not include any steps for sanitizing, validating, or escaping the data fetched from external platforms before it is analyzed.
Audit Metadata