deliver
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data including tickets, specifications, and repository code which are interpolated into the agent's context. A malicious actor could embed instructions within these sources to influence the agent's actions during implementation or review.\n
- Ingestion points: Tickets, specifications, and repository files (references/preflight.md, references/review.md).\n
- Boundary markers: The skill relies on separate workflow phases but does not explicitly use structural delimiters for untrusted content.\n
- Capability inventory: The agent has the ability to modify files and execute shell commands for testing and validation.\n
- Sanitization: The instructions do not specify any filtering or sanitization of external data.\n- [COMMAND_EXECUTION]: The skill is instructed to discover and run validation commands from repository manifests, build configurations, and CI scripts. This is a functional requirement for delivery but involves executing logic defined in the local environment.
Audit Metadata