settle-borrowed-authority
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources which could theoretically contain malicious instructions designed to influence the agent's behavior during the review process.
- Ingestion points: Pull Request metadata (body, comments) retrieved via
gh pr viewand local code content containing 'TEMPORARY AGENT' markers located viagrep. - Boundary markers: The instructions do not define specific delimiters or boundary protections to prevent the agent from interpreting instructions embedded within the PR text or code comments.
- Capability inventory: The skill utilizes file system reads/writes,
gitoperations (commit and push), and GitHub CLI interactions to perform its tasks. - Sanitization: No sanitization, filtering, or strict schema validation is described for the content parsed from the PR body or the tree grep results.
Audit Metadata