apply
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (proposals and issues) while maintaining system modification and execution capabilities.
- Ingestion points: Authoritative proposal and issue states are consumed to derive the feature queue and implementation scope in references/single.md and references/queue.md.
- Boundary markers: The skill specifically instructs the agent in references/recovery.md to treat conversation history as context only and to verify all state against durable evidence.
- Capability inventory: The workflow encompasses file system modifications, execution of builds and tests, and network-based persistence (push, deploy, release) as described in references/completion.md.
- Sanitization: Implementation is subject to mandatory security checks and operational gates before being considered terminal.
Audit Metadata