skills/mthines/agent-skills/severity/Gen Agent Trust Hub

severity

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and evaluate untrusted data in the form of code 'findings' or 'bugs' to determine their severity tier (critical, high, medium, or low). These tiers directly influence downstream actions such as blocking pull requests or triaging incidents, making the assessment a target for manipulation. * Ingestion points: Untrusted data enters the agent context through the '$ARGUMENTS' variable and the associated code content of the bug or finding being analyzed. * Boundary markers: The skill does not define or enforce the use of clear delimiters or 'ignore' instructions for the untrusted content it evaluates. * Capability inventory: The skill itself only produces a text classification and does not have access to tools for network operations, file system writes, or subprocess execution. * Sanitization: There is no evidence of input validation or sanitization mechanisms to prevent the assessed content from containing instructions that attempt to override the assessment rubric itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:40 PM
Security Audit — agent-trust-hub — severity