find-regression
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes repository files and commit messages which could contain malicious instructions. However, it explicitly mitigates this by instructing the agent to treat such content as data.
- Ingestion points: repository files, commit messages, issue text, hooks, and command output in SKILL.md.
- Boundary markers: Explicit instructions to treat external content as data unless authority is independently established.
- Capability inventory: Build execution, test execution, and script execution via git bisect.
- Sanitization: Requirement for manual verification of results and the use of reviewed scripts.
- [DYNAMIC_EXECUTION]: The workflow involves executing local build processes and test scripts. This is the intended primary purpose of the regression tool and includes instructions for isolation and state restoration.
Audit Metadata