post-merge-scan
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill consists exclusively of markdown instructions and does not include any executable scripts, binaries, or configuration files.
- [PROMPT_INJECTION]: The skill processes untrusted data from external sources (PR titles and code diffs), making it susceptible to indirect prompt injection.
- Ingestion points: Scans titles and file contents of recent merges as specified in SKILL.md.
- Boundary markers: The skill does not define specific delimiters to separate user/system instructions from the untrusted data being analyzed.
- Capability inventory: The skill outputs recommendations for automated loops (minimal-fix, ticket, escalate-human).
- Sanitization: No sanitization or instructions to ignore directives found within the analyzed code are provided.
Audit Metadata