point
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The workflow incorporates the execution of software checks to verify changes.
- Evidence: Step 5 of the 'Run the loop' section directs the agent to 'Run the most direct check and the nearest useful regression check.'
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes and modifies source code, which is a surface for indirect prompt injection.
- Ingestion points: Reads software source code and task context in SKILL.md.
- Boundary markers: No specific delimiters or instructions to ignore embedded commands are present.
- Capability inventory: Includes capabilities for file modification and command execution for testing.
- Sanitization: No explicit validation or filtering of the ingested code content is described.
Audit Metadata