hotfix
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from bug reports and user-provided descriptions which are used to drive a high-privilege workflow involving source code edits and shell commands.
- Ingestion points: The skill accepts a
bug-id or descriptionas its primary argument and reads existing bug files inSKILL.md(Phase 4 and Phase 6). - Boundary markers: The instructions do not specify delimiters or provide warnings to the agent to ignore instructions embedded within the bug descriptions.
- Capability inventory: The skill has access to
WriteandEditfor modifying source code,Bashfor executing repository commands (git), and theAgenttool to trigger other skill workflows. - Sanitization: There is no explicit sanitization or validation of the input bug data before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to perform repository management tasks. - Evidence: In Phase 3, the skill executes
git rev-parse --is-inside-work-treeto verify the environment andgit checkout -b hotfix/[short-name] [base-ref]to manage branches. These actions are appropriately gated by theAskUserQuestiontool for user confirmation.
Audit Metadata