should-flag-change

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is explicitly read-only and advisory. It includes robust guardrails that forbid the agent from creating, toggling, or modifying feature flags, and from making any changes to the source code or file system. All findings are delivered through a structured, local advisory tool.
  • [PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection because it processes untrusted input from git diffs and existing source files. However, the risk is mitigated to a safe level by the skill's restricted capability set. Ingestion points: Data enters the agent context via <git_diff> blocks and repository files accessed through Read, Grep, and Glob tools. Boundary markers: The skill instructs users to provide diffs within specific XML-like tags. Capability inventory: The agent is limited to read-only file operations and a specific recommendation tool, with no access to shell commands, write operations, or network exfiltration. Sanitization: The skill relies on a rigid decision framework and explicit behavioral constraints to process input safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 02:02 PM
Security Audit — agent-trust-hub — should-flag-change