loop-triage

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data including CI failures, Linear tickets, Git commits, and Slack threads. This creates a surface for Indirect Prompt Injection, where malicious content in these sources could manipulate the agent's output.\n- Ingestion points: Linear tickets, Slack/chat threads, and commit messages as defined in SKILL.md.\n- Capability inventory: Writing structured output to state files or project management boards.\n- Boundary markers: Absent. The instructions do not define delimiters to separate system instructions from ingested data.\n- Sanitization: Absent. No validation or filtering of external content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:02 PM
Security Audit — agent-trust-hub — loop-triage