buildbetter-project-triage

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize large volumes of external, untrusted data which could contain malicious instructions meant to influence the agent's behavior.
  • Ingestion points: The skill fetches data from Linear tickets (get-linear-ticket), triage items (get-triage-item), and "agent sessions" which may include logs of previous AI interactions (SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate the ingested data or warn the LLM to ignore embedded instructions within these sources.
  • Capability inventory: The skill possesses the capability to modify project states via promote-triage-item and promote-linear-tickets tools.
  • Sanitization: No mention of input validation or sanitization for the content of tickets or evidence is present.
  • Mitigation: The risk is significantly reduced by the "Promotion Workflow" described in SKILL.md, which requires a summary readback to the user and explicit manual approval before any promotion tools are executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 05:47 PM
Security Audit — agent-trust-hub — buildbetter-project-triage