fix-finding
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill is designed to process security findings and attacker-controlled input as part of the remediation workflow. This creates a surface where malicious instructions embedded within a vulnerability report could attempt to influence the agent. The skill addresses this by requiring independent investigation and verification phases.
- [Remediation Verification Commands]: The workflow requires the agent to execute builds, syntax checks, and reproduction scripts to verify fixes. While these are necessary for the skill's purpose, they involve the execution of commands within the local environment based on the code being analyzed.
Audit Metadata