monitor-ci
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exposes an indirect prompt injection vulnerability surface because it processes external data from CI failure logs and automated repair suggestions without containment or validation.
- Ingestion Points: In
SKILL.mdandreferences/fix-flows.md, untrusted text data enters the agent context through fields liketaskFailureSummaries,suggestedFixDescription, andsuggestedFixSummaryfetched by theci_informationtool. - Boundary Markers: Absent. The instructions do not define boundary delimiters or explicit system instructions directing the subagents to ignore embedded natural language commands within logs or fix summaries.
- Capability Inventory: The skill holds a high capability profile across its scripts and references, including running local shell commands via package managers (
pnpm nx,yarn nx,npx nx), altering codebase files, conducting Git operations (git commit,git push), and executing destructive actions or tool updates via MCP. - Sanitization: Absent. No sanitization, escaping, or schema-enforcement filters are applied to raw log fields before passing them to the subagents for analysis.
Audit Metadata