work-item-sequencing

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists of markdown instructions and platform metadata without any scripts or executable files.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a process for interpreting external work item subjects, creating a potential surface for indirect prompt injection. 1. Ingestion points: Subject__c field in GUS work items (referenced in SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Logic involves reading and ordering items using tools like gus-cli (referenced in SKILL.md). 4. Sanitization: Absent.
  • [SAFE]: The logic for sequencing work items follows standard organizational patterns. No unauthorized data exfiltration, obfuscation, or malicious command execution was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:06 AM
Security Audit — agent-trust-hub — work-item-sequencing