project-quality-setup
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements a robust defense-in-depth approach by establishing a "Trust boundary for external evidence," which explicitly instructs the agent to treat external data such as Pull Request bodies, issue comments, and logs as untrusted evidence rather than instructions.
- [SAFE]: It provides detailed guidance to prevent common vulnerabilities, including command injection (by mandating structured arguments and shell quoting) and credential exposure (by forbidding the extraction, printing, or forwarding of secrets discovered during analysis).
- [SAFE]: The skill recommends well-known, standard developer tools for security and quality (e.g., ESLint, Playwright, axe-core, Dependabot, CodeQL) and references their official documentation.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface where the agent ingests untrusted data from GitHub repository artifacts. It mitigates this risk by requiring the agent to verify all factual claims independently against static code and by forbidding the promotion of instructions discovered within reviewed content into the agent's active instruction hierarchy.
Audit Metadata