agent-watchdog
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: Ingestion points: The skill resolves targets from multiple external sources, including session IDs, transcript paths, thread URLs, PRs, branches, CI runs, Slack links, and pasted summaries, all of which are documented in SKILL.md and references/builder-upstream.md.
- [INDIRECT_PROMPT_INJECTION]: Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when processing external transcripts or chat histories.
- [INDIRECT_PROMPT_INJECTION]: Capability inventory: The skill has the authority to perform file writes and execute development lifecycle commands in 'Audit and fix' and 'Takeover' modes.
- [INDIRECT_PROMPT_INJECTION]: Sanitization: The skill lacks defined validation or sanitization protocols for external data before it is incorporated into the reconstructed 'contract' of the task.
Audit Metadata