qstack-babysit-pr
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from pull request comments, reviews, and CI outputs.
- Ingestion points: Processes external data from PR comments, reviews, and CI logs as described in
SKILL.mdunder the "Watch and respond" section. - Boundary markers: Lacks explicit instructions or delimiters to isolate untrusted content from the agent's core instructions.
- Capability inventory: Possesses write access to the filesystem (to fix defects), git operations (commit, push, rebase), and the ability to post comments to external platforms via host tools.
- Sanitization: Does not specify any sanitization, filtering, or validation for the content retrieved from external sources.
Audit Metadata