trust-but-verify

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data, creating a surface for indirect prompt injection attacks.\n
  • Ingestion points: The skill reads external content including git diff main...HEAD, gh pr view output, and plan files located in docs/plans/ (SKILL.md, analysis-prompt.md).\n
  • Boundary markers: While analysis-prompt.md provides a structured template, it lacks explicit delimiters or instructions to the subagent to ignore potentially malicious commands embedded within the ingested data.\n
  • Capability inventory: The skill has access to powerful tools, including Bash for command execution, Write for file system modification, and mcp__playwright__* for browser automation. It also manages a local credential file at reference_local_auth.md.\n
  • Sanitization: There is no evidence of sanitization, filtering, or validation performed on the ingested text before it is analyzed by the subagent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:00 PM
Security Audit — agent-trust-hub — trust-but-verify