buildbetter-project-triage
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize large volumes of external, untrusted data which could contain malicious instructions meant to influence the agent's behavior.
- Ingestion points: The skill fetches data from Linear tickets (
get-linear-ticket), triage items (get-triage-item), and "agent sessions" which may include logs of previous AI interactions (SKILL.md). - Boundary markers: There are no explicit instructions or delimiters defined to isolate the ingested data or warn the LLM to ignore embedded instructions within these sources.
- Capability inventory: The skill possesses the capability to modify project states via
promote-triage-itemandpromote-linear-ticketstools. - Sanitization: No mention of input validation or sanitization for the content of tickets or evidence is present.
- Mitigation: The risk is significantly reduced by the "Promotion Workflow" described in SKILL.md, which requires a summary readback to the user and explicit manual approval before any promotion tools are executed.
Audit Metadata