hotfix
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute Git commands for repository status checks and branch management. These actions are governed by human-in-the-loop checkpoints where the agent must confirm the specific command or branch name with the user before execution.- [INDIRECT_PROMPT_INJECTION]: The skill processes external bug reports which constitutes a potential data ingestion surface. * Ingestion points: Phase 1 reads bug descriptions or IDs from user input or project files. * Boundary markers: The instructions do not specify explicit delimiters or isolation markers for the ingested content. * Capability inventory: The skill possesses capabilities for shell command execution (Bash), file system modification (Edit, Write), and agent delegation (Task). * Sanitization: No explicit sanitization or validation of the input data is defined in the instructions.- [SAFE]: The workflow incorporates rigorous safety gates including mandatory sign-offs from multiple distinct roles (Lead Programmer, QA Tester, Producer) and a formal QA re-entry evaluation before any changes are finalized or deployed.
Audit Metadata