conventions-check
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to analyze untrusted text from pull request titles and descriptions.
- Ingestion points: External content enters the agent context via
args.pullRequestandargs.descriptioninSKILL.md. - Boundary markers: The skill includes a dedicated "Security" section with instructions to treat all PR content as untrusted and to disregard any embedded commands.
- Capability inventory: No capabilities for file system modification, network communication, or shell command execution were detected in the skill instructions.
- Sanitization: The skill relies on natural language instructions for safety rather than programmatic sanitization or strict boundary delimiters for the untrusted input.
Audit Metadata