workflow-fix-and-ship
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted production data through Sentry issues and Supabase logs during the triage phase. This creates an indirect prompt injection surface where malicious data embedded in logs could theoretically attempt to influence the agent's fix strategy. This risk is mitigated by the skill's requirement for manual reproduction steps and the restriction to 'surgical' code changes.
- [COMMAND_EXECUTION]: The skill facilitates high-privilege operations, including database schema modifications and automated pull request creation. These capabilities are consistent with the skill's purpose and are managed through standard MCP tool interfaces.
Audit Metadata