coach
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on analyzing external data sources, specifically git commit logs and modified file contents, to generate its reflection reports. This ingestion of untrusted data creates a surface where malicious strings embedded in commit messages or code diffs could potentially influence the agent's behavior during the reflection process.\n
- Ingestion points: Step 1 in SKILL.md requires the agent to inspect git logs (
git log --since=\"24 hours ago\") and recently modified files.\n - Boundary markers: The instructions do not specify any delimiters or "ignore instructions" warnings to wrap the ingested log data.\n
- Capability inventory: The skill utilizes the
bash,view_file, andwrite_to_filetools to execute commands and manage the standup log artifact.\n - Sanitization: There are no defined steps to sanitize or validate the content extracted from logs before it is processed by the agent.\n- [NO_CODE]: The skill is implemented entirely through prompt instructions, markdown templates, and configuration files, containing no executable scripts (such as .py or .js files).
Audit Metadata