agile-skill-feedback
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) due to its core function of processing external data.
- Ingestion points: The agent is instructed to read '$ARGUMENTS' from a slash command and inspect external 'evidence artifacts' or 'diffs' in its local environment.
- Boundary markers: The instructions do not specify any delimiters (such as XML tags or triple quotes) or 'ignore' instructions to isolate the content of untrusted artifacts from the agent's logic.
- Capability inventory: The skill has permission to read local files (including other skill files) and is expected to generate and write new feedback artifacts based on its analysis.
- Sanitization: There is no requirement or logic provided for sanitizing or validating the contents of the evidence before it is processed by the model.
Audit Metadata