trust-but-verify
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data, creating a surface for indirect prompt injection attacks.\n
- Ingestion points: The skill reads external content including
git diff main...HEAD,gh pr viewoutput, and plan files located indocs/plans/(SKILL.md, analysis-prompt.md).\n - Boundary markers: While
analysis-prompt.mdprovides a structured template, it lacks explicit delimiters or instructions to the subagent to ignore potentially malicious commands embedded within the ingested data.\n - Capability inventory: The skill has access to powerful tools, including
Bashfor command execution,Writefor file system modification, andmcp__playwright__*for browser automation. It also manages a local credential file atreference_local_auth.md.\n - Sanitization: There is no evidence of sanitization, filtering, or validation performed on the ingested text before it is analyzed by the subagent.
Audit Metadata