start

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted external input from user-provided ticket descriptions and local configuration files. Ingestion points: $ARGUMENTS in SKILL.md and CLAUDE.local.md via the context-scouter sub-agent. Boundary markers: No explicit delimiters or ignore-instructions are present in the orchestrator prompts. Capability inventory: The workflow includes subprocess execution (git commit), PR creation, and network interactions. Sanitization: No explicit input sanitization is performed. The workflow includes a mandatory manual approval gate at Phase 3 to mitigate risks of automated execution of malicious plans.
  • [COMMAND_EXECUTION]: The skill executes automated version control operations. Evidence: Phase 4b includes git commit via Bash after task execution.
  • [EXTERNAL_DOWNLOADS]: The skill performs network interactions for quality assurance. Evidence: Phase 6 requests a target URL from the user and passes it to the web-qa-reviewer sub-agent to verify the implemented UI component.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 02:50 AM
Security Audit — agent-trust-hub — start