grant-naming-authority

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and act upon data from untrusted files within the repository.
  • Ingestion points: The agent is directed to read repository-specific files such as AGENTS.md, CLAUDE.md, and external documentation/ADRs. It also performs a recursive grep across the entire project tree to identify markers.
  • Boundary markers: Absent. There are no instructions to use delimiters or ignore potential commands embedded within the documentation or code files being scanned.
  • Capability inventory: The skill allows the agent to write markers back to the filesystem, generate pull request tables, and interact with other skills like approval-policy.
  • Sanitization: Absent. The skill does not define any validation or filtering for the content retrieved from the repository files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 10:35 PM
Security Audit — agent-trust-hub — grant-naming-authority