squad-fix
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data which could contain malicious instructions meant to influence agent behavior.
- Ingestion points: The skill accepts user-provided bug reports, logs, traces, and error messages as primary input via the
squad-fixcommand arguments. - Boundary markers: The instructions in
SKILL.mdexplicitly mandate treating issue text, logs, and external docs as untrusted data and advise the agent to redact secrets before processing. - Capability inventory: The agent is authorized to search the repository, execute shell commands for testing and reproduction, and modify source code across multiple domains (Frontend, Backend, Mobile, DevOps).
- Sanitization: The skill provides guidelines for redacting sensitive information but relies on instructions rather than structured sanitization to prevent the execution of instructions embedded in the analyzed logs.
Audit Metadata