open-work

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill performs automated scanning and summarization of repository content which can serve as a vector for indirect prompt injection.
  • Ingestion points: The scripts scripts/bin/open-items and scripts/bin/triage-list-drafts parse and extract text from proposal.md, tasks.md, and README.md files within the target repository.
  • Boundary markers: There is a lack of explicit boundary markers or isolation instructions when this extracted content (such as proposal summaries) is rendered into the agent's context in scripts/bin/render-open-work.
  • Capability inventory: The skill possesses significant capabilities including shell command execution (shell) and workflow orchestration (apply), which could be targeted by instructions embedded in the ingested data.
  • Sanitization: Content processing is limited to structural normalization (e.g., stripping newlines and truncating length) but does not include sanitization of natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:18 PM
Security Audit — agent-trust-hub — open-work