ask-matt
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill establishes workflows that ingest untrusted external data, such as user-submitted bug reports and feature requests, which could contain malicious instructions.
- Ingestion points: Processes external issues, bug reports, and project documentation (CONTEXT.md).
- Boundary markers: Explicitly defines 'Phase Boundaries' in PHASE-BOUNDARIES.md to manage context and mitigate instruction bleed between tasks, emphasizing the distinction between first-hand and second-hand information.
- Capability inventory: Routes to other skills capable of code implementation, file manipulation, and issue management.
- Sanitization: No specific sanitization or filtering logic is described for the external inputs.
- [SAFE]: The skill provides high-level process documentation and meta-instructions for routing without including any executable scripts or hidden commands.
- [EXTERNAL_DOWNLOADS]: Includes a plain-text link to external documentation at aihero.dev to define technical terminology such as 'smart zones'.
Audit Metadata