oodle-triage

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from multiple external sources. 1. Ingestion points: Production alert signals, Linear or Jira ticket content, and GitHub pull request manifests (SKILL.md). 2. Boundary markers: The instructions do not specify the use of delimiters or isolation markers for external data. 3. Capability inventory: The skill can create, update, comment on, and close tickets in issue trackers, and execute observability queries (SKILL.md). 4. Sanitization: No explicit filtering or validation of ingested content is described before use in the agent's context.
  • [COMMAND_EXECUTION]: The skill utilizes the gh command-line interface to fetch pull request metadata and interacts with various MCP tools for observability and task management (SKILL.md). These operations are standard for the skill's triage purpose and target well-known, legitimate services.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:11 PM
Security Audit — agent-trust-hub — oodle-triage