bug-reporting

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external, potentially untrusted sources such as automated accessibility tool outputs and user reports. This represents a vulnerability surface for indirect prompt injection.
  • Ingestion points: The skill is intended to process 'automated tool output, manual testing, user reports, or testing with disabled people' as defined in SKILL.md.
  • Boundary markers: Instructions require the agent to 'Record observed facts separately from assumptions' and to label the 'evidence basis' clearly, which provides context separation.
  • Capability inventory: The skill does not provide the agent with dangerous capabilities such as arbitrary command execution, network exfiltration, or file system access.
  • Sanitization: The skill contains multiple mandatory instructions to 'remove personal data, credentials, tokens, and private content' from all reports and attachments, significantly mitigating the risks associated with data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:02 PM
Security Audit — agent-trust-hub — bug-reporting