explain-change
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content including pull request descriptions, commit messages, and source code to generate briefings, creating an indirect prompt injection surface.
- Ingestion points: SKILL.md instructs the agent to resolve PR evidence, read commit messages, and analyze repository code.
- Boundary markers: The instructions lack explicit delimiters or warnings to treat ingested content strictly as data.
- Capability inventory: The agent possesses file system read access and potential write/publication capabilities if authorized by the user.
- Sanitization: No explicit filtering, validation, or escaping of ingested text is mentioned.
Audit Metadata