skills/backnotprop/pstack/correct/Gen Agent Trust Hub

correct

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves analyzing repository history and comments, which represents a potential surface for indirect prompt injection if external contributors include instructions in commit messages or code comments.
  • Ingestion points: SKILL.md instructs the agent to read commits, reverts, review comments, and instruction files.
  • Boundary markers: No specific delimiters or safety instructions are provided to separate data from commands during ingestion.
  • Capability inventory: The skill allows the agent to modify repository code, architecture, and CI configurations.
  • Sanitization: No filtering or sanitization of external text is defined.
  • [SAFE]: The skill instructions are standard developer guidance for technical debt reduction and repository health. No malicious behavior, data exfiltration, or unauthorized execution patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 03:05 PM