grant-decision-authority

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon instructions from external, potentially untrusted sources which could be used to influence agent behavior. \n- Ingestion points: The agent reads project specifications, Architecture Decision Records (ADRs), issue tracker tickets, and human feedback within pull request comments. \n- Boundary markers: The protocol requires the use of verbatim tracking strings (TEMPORARY AGENT...) within the source code and structured tables in pull request descriptions to clearly identify non-human decisions. \n- Capability inventory: The agent has the ability to modify source code, update specifications, execute grep for state tracking, and interact with users through AskUserQuestion. \n- Sanitization: Security is maintained through a strict human-in-the-loop requirement; no 'borrowed' decision is considered final or allowed to be merged without explicit human verification and the removal of temporary markers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 01:00 PM
Security Audit — agent-trust-hub — grant-decision-authority