multica-squads
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection through its data ingestion and processing workflows.
- Ingestion points: The agent ingests data from the workspace environment using
multica squad getfor squad instructions andmultica issue comment listfor issue comments (SKILL.md). - Boundary markers: There are no explicit instructions or delimiters defined in the skill files to assist the agent in distinguishing between its core instructions and potentially adversarial instructions embedded in the workspace data.
- Capability inventory: The skill enables the agent to perform state-changing operations including creating, updating, and deleting squads, as well as modifying issue records (SKILL.md).
- Sanitization: The provided documentation does not specify any sanitization, filtering, or validation processes for the data retrieved from external sources before it is processed by the agent.
Audit Metadata