fix
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, specifically bug reports and issue descriptions.
- Ingestion points: Intake and reproduction workflows defined in
SKILL.md(Step 1). - Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded commands within the bug reports.
- Capability inventory: The workflow involves file system modifications (Step 4) and command execution for verification (Step 5).
- Sanitization: The skill does not define specific sanitization or filtering protocols for the input text.
- [SAFE]: The skill implements strong defensive programming practices by defining a 'Scope Gate' and 'Hard Stop Escalation Criteria.' It explicitly forbids proceeding with the skill if security-sensitive behavior is involved or if the scope of changes becomes too broad, which mitigates the risk of unauthorized system changes.
Audit Metadata