check-readiness
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from GitHub, creating a surface for indirect prompt injection where malicious issue content could attempt to influence agent behavior.\n
- Ingestion points: The skill uses
gh issue viewto retrieve the body and comments of issues and implementation plans (SKILL.md).\n - Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the issue content are defined.\n
- Capability inventory: The agent can invoke other skills like
merge-it,$coderabbit-cli, and$autofix, and perform GitHub operations like committing and pushing code (SKILL.md).\n - Sanitization: The skill does not specify any sanitization or validation of the retrieved issue text before processing.
Audit Metadata