specialist-ac-verifier
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process data from external, untrusted sources such as diffs, pull requests, and project management tickets.
- Ingestion points: Processes PR diffs, implementation evidence, and external ticket text from Jira, GitHub, GitLab, ADO, and Zephyr (SKILL.md).
- Boundary markers: The instructions lack specific guidance for the agent to use delimiters or to ignore instructions that may be embedded within the ticket descriptions or code comments being analyzed.
- Capability inventory: The skill utilizes code graph and ticket MCP tools to read source files and metadata, which provides a capability surface for injected instructions to affect the analysis outcome (SKILL.md).
- Sanitization: No specific sanitization or validation protocols are defined for the content extracted from external tools or local artifacts.
Audit Metadata