multica-platform
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to process potentially untrusted data from GitHub pull requests and issue comments, defining an attack surface for indirect prompt injection.\n * Ingestion points: Data enters via commands such as
multica issue comment listandmultica issue pull-requestsdescribed inreferences/mentions.mdandreferences/issues.md.\n * Boundary markers: The platform utilizes specific Markdown patterns[@Label](mention://...)for mentions, which provides a structural delimiter for actionable platform links.\n * Capability inventory: The agent has access to powerful CLI tools includingmultica,git, andghas defined inSKILL.md.\n * Sanitization: The documentation instructs agents to validate UUIDs against live rosters and follow strict role-based access rules, mitigating risks of unauthorized actions.\n- [EXTERNAL_DOWNLOADS]: The skill describes the process for importing AI agent skills from external sources using themultica skill importcommand.\n * Evidence: Thereferences/skill-import.mdfile documents importing skills from GitHub, ClawHub, and Skills.sh, which are recognized platform ecosystem sources and well-known services.
Audit Metadata