pr-description
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data from the repository environment, creating a surface for indirect prompt injection.\n
- Ingestion points: The agent is instructed to read repository instructions, pull request templates, code diffs, commit lists, and linked issue specifications (SKILL.md).\n
- Boundary markers: The instructions lack explicit directives for using delimiters or boundary markers to isolate potentially malicious instructions embedded in the external content.\n
- Capability inventory: The skill's functionality is limited to generating text summaries and does not explicitly invoke high-privilege tools for file system modification, network communication, or code execution.\n
- Sanitization: No filtering or sanitization steps are defined for the content ingested from the external repository files.
Audit Metadata