fix-it
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Failing URLs, browser-visible symptoms, logs, traces, metrics, and reproduction inputs are ingested into the agent's context (SKILL.md).
- Boundary markers: The skill employs a structured output template with markdown headers (Observed Symptom, Evidence, etc.) to organize data, but it does not explicitly instruct the agent to ignore instructions embedded within the ingested data.
- Capability inventory: The skill utilizes tools for repository inspection (rg), targeted file reads, and commands for managing issues and pull requests (issues create, pulls create, merge-it).
- Sanitization: There is no explicit requirement for the agent to sanitize, escape, or validate external content before incorporating it into the fix plan.
Audit Metadata