story-pr-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external repository artifacts which could contain hidden instructions or malicious content intended to manipulate the orchestration process.
- Ingestion points: The skill reads repository instructions, specifications, task lists, status documents, and transcripts from the repository environment (SKILL.md, Section 1).
- Boundary markers: The instructions do not explicitly require the use of separators (like XML tags or specific delimiters) or warn the agent to ignore instructions embedded within these data sources.
- Capability inventory: The skill manages critical infrastructure including branches, worktrees, and pull requests, and it generates detailed briefs for child agents (SKILL.md, Sections 3, 4, 6).
- Sanitization: The skill incorporates a conflict resolution strategy that ranks sources by authority and date, and requires documenting blockers when sources conflict, which acts as a verification mechanism (SKILL.md, Section 1).
Audit Metadata