positron-intake-rotation

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external GitHub issues and discussions, creating a potential surface for indirect prompt injection. \n- Ingestion points: External content enters the context via scripts/fetch_intake_issues.sh and scripts/fetch_discussions.sh. \n- Boundary markers: No explicit delimiters or boundary markers for untrusted external content are defined in the instructions. \n- Capability inventory: The skill utilizes read-only gh CLI commands and local search scripts; it does not possess tools or instructions to modify the repository or system state directly. \n- Sanitization: A strict 'Manual Action Protocol' is enforced, requiring all drafted responses and commands to be manually reviewed and executed by the human user. \n- [SAFE]: The skill references external URLs for Jira, Google Sheets, and project documentation (positron.posit.co). These references are legitimate resources belonging to the project maintainers and are appropriate for the skill's stated purpose of issue triage.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 03:33 PM
Security Audit — agent-trust-hub — positron-intake-rotation