address-feedback

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from multiple external sources, including Notion, Google Docs, Linear, GitHub, Slack, and public URLs, as described in Step 1. This creates a surface for indirect prompt injection.\n
  • Ingestion points: Feedback content from various documented and public sources.\n
  • Boundary markers: None present in the instructions.\n
  • Capability inventory: Source code modification, test execution, and web browsing.\n
  • Sanitization: No explicit sanitization or validation of external content.\n- [COMMAND_EXECUTION]: The skill utilizes command-line tools such as 'gh issue view' and 'gh pr view' to retrieve feedback, and executes local test/typecheck commands to verify fixes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 07:51 AM
Security Audit — agent-trust-hub — address-feedback