line
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external technical 'branches' and user requests, representing a surface for instructions embedded in untrusted data to influence agent behavior.
- Ingestion points: Data enters the agent context through 'branches' passed from the 'Plane' skill and direct user requests as described in
SKILL.md. - Boundary markers: The skill instructions focus on 'domain boundaries' and 'boundary meaning' to scope work, though these serve as logical constraints rather than technical sanitization filters.
- Capability inventory: The skill manages the coordination of the
pointskill to 'make changes' and 'fix causes', implying file system modification capabilities in the broader agent environment. - Sanitization: The skill lacks explicit instructions for sanitizing or escaping the content provided in external branches or user requests before the agent acts upon them.
Audit Metadata