multica-platform

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to process potentially untrusted data from GitHub pull requests and issue comments, defining an attack surface for indirect prompt injection.\n * Ingestion points: Data enters via commands such as multica issue comment list and multica issue pull-requests described in references/mentions.md and references/issues.md.\n * Boundary markers: The platform utilizes specific Markdown patterns [@Label](mention://...) for mentions, which provides a structural delimiter for actionable platform links.\n * Capability inventory: The agent has access to powerful CLI tools including multica, git, and gh as defined in SKILL.md.\n * Sanitization: The documentation instructs agents to validate UUIDs against live rosters and follow strict role-based access rules, mitigating risks of unauthorized actions.\n- [EXTERNAL_DOWNLOADS]: The skill describes the process for importing AI agent skills from external sources using the multica skill import command.\n * Evidence: The references/skill-import.md file documents importing skills from GitHub, ClawHub, and Skills.sh, which are recognized platform ecosystem sources and well-known services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:58 PM
Security Audit — agent-trust-hub — multica-platform