automation-triage
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from an external capture file, which constitutes a potential surface for indirect prompt injection attacks.
- Ingestion points: Loads ordered process steps from
{sops-dir}/{slug}/{slug}-capture.mdat the beginning of the workflow. - Boundary markers: There are no instructions providing specific delimiters or directives to the agent to disregard instructions that may be embedded within the capture file.
- Capability inventory: The skill is authorized to read and write files within the project directory to generate its report but has no access to network tools or shell command execution.
- Sanitization: The instructions do not define any filtering, validation, or sanitization steps for the data retrieved from the capture file.
- [NO_CODE]: The skill consists entirely of natural language instructions and does not include any executable scripts, binaries, or third-party package dependencies.
Audit Metadata