project-flow-ops
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub (issues, pull requests, and comments), creating a surface for indirect prompt injection.
- Ingestion points: Processes state, comments, and linked issue content from GitHub as described in the 'Core Workflow' section of
SKILL.md. - Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings for external data.
- Capability inventory: The skill is intended to perform read and write operations on GitHub and Linear via the agent's environment tools.
- Sanitization: The skill mitigates potential injection risks by explicitly instructing the agent to never trust summaries or titles and to always base decisions on the full code diff.
Audit Metadata