gc-work
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to ingest and process external task data (beads), which establishes a potential surface for indirect prompt injection. \n- Ingestion points: The agent reads external content via the
gc bd showandgc hookcommands (SKILL.md).\n- Boundary markers: Absent; there are no instructions to use specific delimiters or ignore embedded instructions within the bead content.\n- Capability inventory: The skill utilizes thegc bd updateandgc bd closecommands to modify the status and metadata of work items (SKILL.md).\n- Sanitization: Absent; the skill does not describe any validation or sanitization steps for the data processed from the CLI output.
Audit Metadata