symphony-mister-smith-review-dispatch

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define a standard workflow for pull request and issue management using provided tools. No malicious patterns, unauthorized network access, or credential exposure were detected. All identified tools and workflows are consistent with the skill's stated purpose.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface: The skill interacts with external data (issue descriptions and PR statuses) through tools like review_merge_status and get_issue_execution_snapshot. While no malicious behavior is present, this represents a surface where the agent could ingest instructions from external repository content.
  • Ingestion points: PR and issue metadata/content retrieved via tool outputs.
  • Boundary markers: Not present; the skill does not explicitly instruct the agent to ignore embedded instructions in the processed PR/issue data.
  • Capability inventory: The skill utilizes tools to view repo-wide status and resolve issue lifecycles.
  • Sanitization: No explicit sanitization or filtering of external data is defined in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 07:42 AM
Security Audit — agent-trust-hub — symphony-mister-smith-review-dispatch