story-pr-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external repository artifacts which could contain hidden instructions or malicious content intended to manipulate the orchestration process.
  • Ingestion points: The skill reads repository instructions, specifications, task lists, status documents, and transcripts from the repository environment (SKILL.md, Section 1).
  • Boundary markers: The instructions do not explicitly require the use of separators (like XML tags or specific delimiters) or warn the agent to ignore instructions embedded within these data sources.
  • Capability inventory: The skill manages critical infrastructure including branches, worktrees, and pull requests, and it generates detailed briefs for child agents (SKILL.md, Sections 3, 4, 6).
  • Sanitization: The skill incorporates a conflict resolution strategy that ranks sources by authority and date, and requires documenting blockers when sources conflict, which acts as a verification mechanism (SKILL.md, Section 1).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 09:08 AM
Security Audit — agent-trust-hub — story-pr-orchestrator