mpm-postmortem
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious instructions, obfuscation, or data exfiltration patterns were detected in the skill configuration.
- [NO_CODE]: The file serves as metadata and usage documentation for an external command; it does not contain executable logic or script content.
- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by design, as it ingests untrusted data (error logs from scripts and user code) to generate automated fixes.
- Ingestion points: Error logs originating from scripts, skills, agents, and user code (SKILL.md).
- Boundary markers: No delimiters or instructions to ignore embedded content are specified in this documentation.
- Capability inventory: The skill supports high-privilege operations including
--auto-fix(file modification) and--create-prs(remote repository updates). - Sanitization: No sanitization or validation steps for the analyzed error content are described in the provided file.
Audit Metadata