arc
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, such as prompt injection, data exfiltration, or obfuscated content, were detected. The skill instructions specifically reinforce security boundaries by requiring human-in-the-loop for credentials and authority grants.
- [COMMAND_EXECUTION]: The skill utilizes standard development and orchestration tools including git, the GitHub CLI (gh), make, and platform-specific utilities (bstack, claude, CronList, CronDelete). These commands are employed for legitimate repository management and session lifecycle control.
- [INDIRECT_PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests data from external sources like Pull Request metadata and repository state.
- Ingestion points: External data enters the context via gh pr view, git status, and the conversation transcript.
- Boundary markers: The instructions emphasize providing verbatim output and "quoted checks" to establish evidence, which offers structural separation, though no explicit delimiters for ignoring embedded instructions are mandated.
- Capability inventory: The skill possesses capabilities for repository mutation (git/gh), file system management, and sub-agent orchestration (bstack, Agent tool).
- Sanitization: No specific sanitization or filtering logic is prescribed for tool outputs before they are processed by the agent.
Audit Metadata