review-assumptions
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and act upon data from external session reports, which could potentially contain instructions intended to influence the agent's behavior.
- Ingestion points: Data is extracted from
codagent:session-reportfiles during the 'Extracting findings' phase. - Boundary markers: The skill does not define specific delimiters or 'ignore' instructions for the content being extracted from reports, though it does use a subagent to help isolate the extraction process.
- Capability inventory: The agent is instructed to perform code edits, execute commits, and dispatch subagents based on the findings in the reports.
- Sanitization: No explicit sanitization or escaping of the report content is mentioned, although the skill requires 'spot-checks' and evidence citation to verify claims made in the reports before acting.
Audit Metadata