fix
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data during its investigation and implementation phases which could potentially contain malicious instructions.
- Ingestion points: External data is ingested from application logs, database state, and GitHub pull request comments, which are subsequently passed to subagents via prompt interpolation (e.g., {user_description} and {diagnosis.pr_comments} in SKILL.md).
- Boundary markers: The prompts for subagents like 'sleuth' and 'kraken' do not employ explicit delimiters or instruction isolation for user-provided data.
- Capability inventory: The skill has access to powerful tools including Bash for command execution, Write and Edit for file modification, and Task for spawning autonomous subagents.
- Sanitization: The workflow does not include explicit sanitization or filtering of the ingested external content before it is processed by subagents.
- Mitigation: The risk is mitigated by mandatory human-in-the-loop checkpoints (AskUserQuestion) that occur after diagnosis, after risk assessment, and before the final commit, ensuring that the AI agent cannot perform unauthorized or harmful modifications without direct user approval.
Audit Metadata