swe-workflow
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides a robust set of instructions and templates for managing complex coding tasks. It prioritizes evidence-based decision-making and surgical code changes. Analysis of the behavioral guards and core contract confirms the skill is focused on quality and structured output rather than harmful operations.- [PROMPT_INJECTION]: The skill facilitates the ingestion of data and instructions from the target repository being processed, which could contain adversarial content.
- Ingestion points:
references/command-discovery.md(scans repository files likepackage.json,Makefile, andAGENTS.mdfor executable commands) andreferences/require-clarification.md(instructs the agent to read the codebase to understand context). - Boundary markers: Absent. The skill does not explicitly instruct the agent to ignore or delimit instructions found within the repository files it reads.
- Capability inventory: The agent has access to
bashfor command execution,readfor file access, andwrite/editfor file modification across the entire repository. - Sanitization: None. The skill instructs the agent to 'discover' and 'record' commands from the repo but does not provide logic for validating the safety of these commands before execution.
Audit Metadata