skills/howells/skills/rebalance/Gen Agent Trust Hub

rebalance

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data retrieved from external project trackers, including item descriptions, acceptance criteria, comments, and pull request data. An attacker with access to the project tracker could embed malicious instructions in these fields to influence the agent's rebalancing logic or tracker update operations.
  • Ingestion points: Project tracker items, descriptions, comments, linked PRs, and specifications in SKILL.md.
  • Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded prompts within the fetched tracker data.
  • Capability inventory: The skill has the ability to write to the project tracker (updating priorities, statuses, and dependency links) and create new items as described in SKILL.md. It can also delegate tasks to other agents.
  • Sanitization: No sanitization or validation of the retrieved tracker content is mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:17 AM
Security Audit — agent-trust-hub — rebalance