day-one-patch
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from bug reports in production/qa/bugs/*.md. (1) Ingestion points: Phase 1 reads all reports with 'Open' or 'Pending' status. (2) Boundary markers: No delimiters are specified to distinguish bug data from agent instructions. (3) Capability inventory: Phase 4 spawns sub-agents with Write, Edit, and Bash permissions to act on the data. (4) Sanitization: No filtering or validation of bug report content is mentioned in the workflow.
Audit Metadata