sitrep
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources such as git history, pull request bodies, and issue descriptions, which are potential vectors for indirect prompt injection.\n
- Ingestion points: The skill instructions in
SKILL.mddirect the agent to read the working tree (git status,git diff,git log) and session artefacts including files, issues, and PR bodies.\n - Boundary markers: The skill does not define or use specific boundary markers or delimiters to isolate the ingested external content from its internal instructions.\n
- Capability inventory: The skill primarily serves a reporting function and does not possess capabilities for network operations, high-privilege file modifications, or remote code execution.\n
- Sanitization: There are no instructions provided for sanitizing, escaping, or filtering content retrieved from git metadata or external project artefacts before it is summarized.
Audit Metadata