skills/chidiokoene/optimal-brain/qa/Gen Agent Trust Hub

qa

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection (Category 8). \n
  • Ingestion points: User conversation, files read by the 'Explore' subagent, and UBIQUITOUS_LANGUAGE.md. \n
  • Boundary markers: Absent. No specific delimiters or warnings are used to separate untrusted data from instructions. \n
  • Capability inventory: GitHub issue creation (gh issue create) and codebase exploration. \n
  • Sanitization: Absent. Ingested data is used to construct issue bodies without validation or filtering.\n- [DATA_EXFILTRATION]: Potential for sensitive data exposure. The skill reads codebase content and publishes behavior descriptions to GitHub. While it explicitly instructs the agent to avoid file paths and internal details, there is a residual risk that sensitive logic or secrets found during exploration could be leaked into the public issue body.\n- [COMMAND_EXECUTION]: The skill executes the 'gh issue create' command. This is used to transmit data derived from potentially untrusted sources (codebase and user input) to an external platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 10:39 PM
Security Audit — agent-trust-hub — qa