eli5
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process external, potentially untrusted data from technical artifacts and code repositories.
- Ingestion points: Referenced technical artifacts, working tree changes, and branch diffs as specified in the Workflow section.
- Boundary markers: No specific delimiters or instructions are provided to the agent to distinguish between the skill's instructions and the content of the technical artifacts being explained.
- Capability inventory: The skill is primarily focused on information processing and text generation to create explanations; it does not explicitly invoke high-privilege tools like network access or file system modification within its instructions.
- Sanitization: There are no mentions of sanitizing, escaping, or filtering the content of the processed artifacts before they are used to generate the explanation.
Audit Metadata