monitor-ci

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes an indirect prompt injection vulnerability surface because it processes external data from CI failure logs and automated repair suggestions without containment or validation.
  • Ingestion Points: In SKILL.md and references/fix-flows.md, untrusted text data enters the agent context through fields like taskFailureSummaries, suggestedFixDescription, and suggestedFixSummary fetched by the ci_information tool.
  • Boundary Markers: Absent. The instructions do not define boundary delimiters or explicit system instructions directing the subagents to ignore embedded natural language commands within logs or fix summaries.
  • Capability Inventory: The skill holds a high capability profile across its scripts and references, including running local shell commands via package managers (pnpm nx, yarn nx, npx nx), altering codebase files, conducting Git operations (git commit, git push), and executing destructive actions or tool updates via MCP.
  • Sanitization: Absent. No sanitization, escaping, or schema-enforcement filters are applied to raw log fields before passing them to the subagents for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:31 PM
Security Audit — agent-trust-hub — monitor-ci