bug-report
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill has an
Analyze Modethat reads target files to identify potential bugs. If these files contain malicious instructions, they could influence the agent's behavior during the analysis phase. The evidence chain is as follows: - Ingestion points: Reads local files specified in the
analyze [path]argument (SKILL.md). - Boundary markers: None explicitly defined to separate code content from analysis instructions.
- Capability inventory: The skill has access to
Bash,Glob,Grep, andmcp__backlog__task_create(SKILL.md). - Sanitization: None mentioned for the ingested file content.
Audit Metadata