finding-discovery

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill analyzes untrusted source code, commit messages, and PR titles (SKILL.md). This ingestion of external data is the skill's primary function. It includes a mandatory evidence chain: 1) Ingestion points: code diffs and commit metadata; 2) Boundary markers: usage of structured scan artifacts like rank_input.jsonl; 3) Capability inventory: local script execution and file inspection tools; 4) Sanitization: instructions to prioritize code analysis over narratives.
  • [Dynamic Execution]: The workflow includes the execution of a local Python script (generate_rank_input.py) to process repository diffs. This is a standard operational pattern for security scanning tools and is used to manage scan metadata and review inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:46 AM
Security Audit — agent-trust-hub — finding-discovery