software-engineering-excellence
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to process and act upon untrusted data from various project sources, creating an attack surface for indirect prompt injection.
- Ingestion points: In SKILL.md and references/investigation.md, the agent is instructed to read and verify source code, issue text, comments, and external project implementations.
- Boundary markers: While SKILL.md mentions isolating workers and using isolated contexts to prevent history inheritance, it does not provide specific delimiters or boundary markers to separate untrusted content from the agent's instructions.
- Capability inventory: The agent is granted the authority to execute commands within the repository, including running reproductions, artifacts, and repository gates, as well as performing deployments, as noted in SKILL.md and references/structural-delivery.md.
- Sanitization: The skill lacks explicit instructions for sanitizing or validating external input before it is processed or interpolated into the agent's reasoning path.
Audit Metadata