bug-report

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill has an Analyze Mode that reads target files to identify potential bugs. If these files contain malicious instructions, they could influence the agent's behavior during the analysis phase. The evidence chain is as follows:
  • Ingestion points: Reads local files specified in the analyze [path] argument (SKILL.md).
  • Boundary markers: None explicitly defined to separate code content from analysis instructions.
  • Capability inventory: The skill has access to Bash, Glob, Grep, and mcp__backlog__task_create (SKILL.md).
  • Sanitization: None mentioned for the ingested file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 04:18 PM
Security Audit — agent-trust-hub — bug-report