systemic-issue-triage

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection due to processing untrusted data with significant capabilities. * Ingestion points: bug reports and community reports processed by systemic-issue-triage in SKILL.md. * Boundary markers: Absent; there are no instructions to delimit or ignore instructions within external data. * Capability inventory: The agent is tasked with executing shell commands to verify exits, reproducing scenarios on fresh binaries, and performing repository-wide grep operations. * Sanitization: Absent; no validation or escaping of external issue text is described.
  • [COMMAND_EXECUTION]: The skill mandates that the agent 'verify runnability by executing the printed command' and 'reproduce the original report's exact scenario'. This introduces the risk of executing arbitrary commands contained within malicious user-submitted issue reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:22 AM
Security Audit — agent-trust-hub — systemic-issue-triage