find-regression

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes repository files and commit messages which could contain malicious instructions. However, it explicitly mitigates this by instructing the agent to treat such content as data.
  • Ingestion points: repository files, commit messages, issue text, hooks, and command output in SKILL.md.
  • Boundary markers: Explicit instructions to treat external content as data unless authority is independently established.
  • Capability inventory: Build execution, test execution, and script execution via git bisect.
  • Sanitization: Requirement for manual verification of results and the use of reviewed scripts.
  • [DYNAMIC_EXECUTION]: The workflow involves executing local build processes and test scripts. This is the intended primary purpose of the regression tool and includes instructions for isolation and state restoration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 03:46 AM
Security Audit — agent-trust-hub — find-regression