skills/i9wa4/dotfiles/collaboration/Gen Agent Trust Hub

collaboration

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data, creating a surface for indirect prompt injection.\n
  • Ingestion points: The agent is instructed to fetch full conversation histories (body and comments) from GitHub issues and pull requests, and reads content from Jira and Confluence REST APIs (references/github-workflow.md, references/atlassian.md).\n
  • Boundary markers: No specific delimiters or instructions to disregard embedded commands are defined for the content fetched from these external platforms.\n
  • Capability inventory: The agent has access to git commit and push operations, the gh CLI for API calls, and authenticated Atlassian REST APIs for Jira and Confluence.\n
  • Sanitization: There is no mention of sanitizing, validating, or filtering the content retrieved from these external sources before it is processed by the agent.\n
  • Mitigation: The skill includes significant mitigations, such as requiring human approval for sensitive actions like pushes and commits, and using safe verification scripts that print only 'set' or 'missing' for credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 01:19 PM
Security Audit — agent-trust-hub — collaboration