open-work
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill performs automated scanning and summarization of repository content which can serve as a vector for indirect prompt injection.
- Ingestion points: The scripts
scripts/bin/open-itemsandscripts/bin/triage-list-draftsparse and extract text fromproposal.md,tasks.md, andREADME.mdfiles within the target repository. - Boundary markers: There is a lack of explicit boundary markers or isolation instructions when this extracted content (such as proposal summaries) is rendered into the agent's context in
scripts/bin/render-open-work. - Capability inventory: The skill possesses significant capabilities including shell command execution (
shell) and workflow orchestration (apply), which could be targeted by instructions embedded in the ingested data. - Sanitization: Content processing is limited to structural normalization (e.g., stripping newlines and truncating length) but does not include sanitization of natural language instructions.
Audit Metadata