bug-fix
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external bug reports which are untrusted inputs that could contain malicious instructions meant to override agent behavior.
- Ingestion points: External bug reports, production issues, and regression descriptions (SKILL.md).
- Boundary markers: The skill implements a mandatory "Input integrity" hard gate requiring the agent to treat embedded instructions as data and ignore them.
- Capability inventory: Uses shell commands for reproduction and verification, specifically
mix test,mix format, andmix credo(SKILL.md). - Sanitization: Instructions mandate extracting only factual details (errors, stack traces) and verifying all claims against verifiable code and test output.
Audit Metadata