project-flow-ops

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub (issues, pull requests, and comments), creating a surface for indirect prompt injection.
  • Ingestion points: Processes state, comments, and linked issue content from GitHub as described in the 'Core Workflow' section of SKILL.md.
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings for external data.
  • Capability inventory: The skill is intended to perform read and write operations on GitHub and Linear via the agent's environment tools.
  • Sanitization: The skill mitigates potential injection risks by explicitly instructing the agent to never trust summaries or titles and to always base decisions on the full code diff.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — project-flow-ops