pre-flight-check

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it instructs the agent to process untrusted data (code changes and Pull Request content) and provides instructions to execute shell commands based on those changes.
  • Ingestion points: Code changes, route handlers, service layers, and PR descriptions (SKILL.md).
  • Boundary markers: Absent; the instructions do not define delimiters or provide warnings to ignore embedded instructions in the processed code.
  • Capability inventory: The skill instructs the agent to execute shell commands including tsc, npm run typecheck, and curl (SKILL.md).
  • Sanitization: Absent; there is no mention of sanitizing or validating the code or PR content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 05:12 AM
Security Audit — agent-trust-hub — pre-flight-check