repo-scanning
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a simulated environment for testing repository triage workflows. It utilizes specific MCP tools (
mcp__triage__search_issues,mcp__triage__inspect_recent_commits, etc.) which, according to the provided runtime contract, generate deterministic synthetic objects and perform no actual network, GitHub API, or filesystem operations. All findings confirm the skill behaves as described without requesting unauthorized access or exfiltrating data. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential injection surface where user-supplied strings (symptoms, error messages, repository names) are ingested and processed.
- Ingestion points:
SKILL.md(argument-hint: "<owner/repo> "). - Boundary markers: Present. The instructions mandate prefixing all summaries with "Synthetic and unverified" and including an "explicit no-network/no-GitHub statement".
- Capability inventory: The skill uses
Readandmcp__triage__*tools which are restricted to providing stubs and perform no external actions. - Sanitization: The skill enforces strict labeling and categorization of all output as prototype/synthetic, effectively neutralizing the risk of embedded instructions in the input strings being mistaken for valid system commands or factual data.
- [EXTERNAL_DOWNLOADS]: The skill references the author's official GitHub repository (
github.com/jeremylongshore/x-bug-triage-plugin) for source code and documentation. This reference is consistent with the skill's stated purpose and originates from the vendor's own infrastructure.
Audit Metadata