specialist-ac-verifier

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process data from external, untrusted sources such as diffs, pull requests, and project management tickets.
  • Ingestion points: Processes PR diffs, implementation evidence, and external ticket text from Jira, GitHub, GitLab, ADO, and Zephyr (SKILL.md).
  • Boundary markers: The instructions lack specific guidance for the agent to use delimiters or to ignore instructions that may be embedded within the ticket descriptions or code comments being analyzed.
  • Capability inventory: The skill utilizes code graph and ticket MCP tools to read source files and metadata, which provides a capability surface for injected instructions to affect the analysis outcome (SKILL.md).
  • Sanitization: No specific sanitization or validation protocols are defined for the content extracted from external tools or local artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:56 AM
Security Audit — agent-trust-hub — specialist-ac-verifier