hada-scout

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection via ingestion of external feed data.
  • Ingestion points: The skill fetches titles and URLs from the external FeedBurner RSS feed at https://feeds.feedburner.com/geeknews-feed (SKILL.md).
  • Boundary markers: Untrusted titles are interpolated into the Phase 2 relevance scoring prompt using a simple {numbered_item_list} placeholder without explicit delimiters or instructions for the agent to ignore embedded instructions.
  • Capability inventory: The skill can execute the GitHub CLI (gh issue list) to check for duplicates and invoke the /scout tool to create new issues with labels on the baekenough/oh-my-customcode repository.
  • Sanitization: External titles and content from the RSS feed are processed as provided without sanitization or verification before being passed to the filtering LLM or downstream analysis tools.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — hada-scout