check-readiness

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from GitHub, creating a surface for indirect prompt injection where malicious issue content could attempt to influence agent behavior.\n
  • Ingestion points: The skill uses gh issue view to retrieve the body and comments of issues and implementation plans (SKILL.md).\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the issue content are defined.\n
  • Capability inventory: The agent can invoke other skills like merge-it, $coderabbit-cli, and $autofix, and perform GitHub operations like committing and pushing code (SKILL.md).\n
  • Sanitization: The skill does not specify any sanitization or validation of the retrieved issue text before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — check-readiness