to-spec
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository and conversation context and uses it to perform a write operation to an external system.
- Ingestion points: The skill instructions direct the agent to explore the repository codebase and synthesize the current conversation context (SKILL.md).
- Capability inventory: The agent has the capability to publish synthesized content to a project issue tracker (SKILL.md).
- Boundary markers: No specific delimiters or instructions are provided to help the agent distinguish between its instructions and potentially malicious content within the repository or chat history.
- Sanitization: There are no explicit instructions for sanitizing or validating the content extracted from the repository before it is published to the issue tracker.
Audit Metadata