settle-borrowed-authority

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources which could theoretically contain malicious instructions designed to influence the agent's behavior during the review process.
  • Ingestion points: Pull Request metadata (body, comments) retrieved via gh pr view and local code content containing 'TEMPORARY AGENT' markers located via grep.
  • Boundary markers: The instructions do not define specific delimiters or boundary protections to prevent the agent from interpreting instructions embedded within the PR text or code comments.
  • Capability inventory: The skill utilizes file system reads/writes, git operations (commit and push), and GitHub CLI interactions to perform its tasks.
  • Sanitization: No sanitization, filtering, or strict schema validation is described for the content parsed from the PR body or the tree grep results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:17 PM
Security Audit — agent-trust-hub — settle-borrowed-authority