retro
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves ingesting data from external, potentially untrusted sources.
- Ingestion points:
collect-review-findings.pyfetches review threads, bodies, and comments from GitHub and GitLab.scan-memory-inventory.pyreads project-local memory files.opencode-transcript.pyreads session databases. - Boundary markers: The scripts do not appear to wrap this external content in clear delimiters or include explicit instructions for the model to ignore embedded commands, though documentation in
feedback-contract.mdacknowledges the risk. - Capability inventory: The skill uses
subprocess.runto callgit,gh, andglab, and utilizes theWriteandEdittools to modify project files and open PRs. - Sanitization: The
mask-secrets.pyutility provides extensive masking for various credential formats (AWS, GitHub, GitLab, etc.).collect-review-findings.pyuses aonelinefunction to strip control characters from foreign content. - [EXTERNAL_DOWNLOADS]: The script
check-upstream-sources.pyperforms network probes (usingurllib.request.urlopen) to arbitrary URLs extracted from markdown documentation. While this is used for link validation during audits, it represents a network activity surface using data derived from potentially user-controlled or external markdown content. - [COMMAND_EXECUTION]: Multiple scripts (
check-eval-samples.py,collect-review-findings.py,scan-cross-session.py,derive-session-scope.py) execute system commands likegit,gh, andglab. Although they use list-based arguments and--end-of-optionsto prevent shell injection, these scripts provide the agent with broad capabilities to interact with local and remote repositories.
Audit Metadata