repo-research-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external repository files, including documentation and specifically 'CLAUDE.md' (a file dedicated to providing instructions to AI assistants), which could contain malicious instructions designed to hijack the agent's behavior during analysis.
  • Ingestion points: The skill reads README.md, CONTRIBUTING.md, ARCHITECTURE.md, CLAUDE.md, and various GitHub templates (.github/ISSUE_TEMPLATE/*.md, .github/PULL_REQUEST_TEMPLATE.md) as specified in the 'Research Process' section of SKILL.md.
  • Boundary markers: The instructions do not provide explicit delimiters or warnings to the agent to treat content from the analyzed repository as untrusted data.
  • Capability inventory: The skill utilizes standard file system discovery commands (ls, find, head) and performs file read operations. It is designed to write its findings to a research handoff file in a specified directory.
  • Sanitization: No sanitization, escaping, or validation of the content read from the repository is implemented before the agent processes the information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — repo-research-analyst