factory
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external GitHub issues and automated review comments, using this information to generate and execute code without human oversight.
- Ingestion points: The
SKILL.mdfile accepts a GitHub issue number or URL as a primary argument. The agent is further instructed in steps 1 and 6 to review the issue content and automated review comments. - Boundary markers: Absent. The instructions do not provide delimiters or warnings to distinguish between the issue's data and potential malicious instructions embedded within that data.
- Capability inventory: The skill possesses significant capabilities, including file system writes (writing specs, code, and tests), shell command execution (running tests), and network interaction through the
ghCLI and git commands. - Sanitization: Absent. There is no mention of sanitizing or validating the content retrieved from the GitHub issue before the agent implements the technical specification.
- [COMMAND_EXECUTION]: The skill is designed to autonomously execute generated code and tests, which creates a risk if the generated code is influenced by a malicious prompt injection.
- Evidence: Step 3 ("Run the tests and fix any failures") and Step 5/6 ("Fix any failures and push") instruct the agent to run and debug code that it has recently authored based on the external issue description.
Audit Metadata