recon
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads and processes external data that could be controlled by an attacker, such as git commit messages, GitHub issue descriptions, and comments. This data is used to determine the scope of work and recommend next actions.
- Ingestion points: The skill uses
git log,git status,git diff,gh issue view,gh pr list, andgh apito gather situational awareness. It also reads project documentation files likeAGENTS.mdandREADME.mdin the current repository. - Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the ingested data defined in the skill instructions.
- Capability inventory: The skill has the capability to read files, run git commands, and use the GitHub CLI. While it primarily scouts for information, it can transition to implementation tasks (file writes) and GitHub interactions (comments, branch management) if authorized by the user.
- Sanitization: No explicit sanitization or validation of the external content is performed before it is processed by the agent to define the plan.
Audit Metadata