complete-work
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon requirements from external, potentially untrusted sources.
- Ingestion points: Task descriptions from Linear tickets, issues, user conversation history, and repository-level configuration files such as
AGENTS.md. - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" warnings to help the agent distinguish between data to be processed and instructions to be followed within external content.
- Capability inventory: The skill possesses significant capabilities, including local file modification, Git branch management, committing code, and pushing changes to remote repositories.
- Sanitization: There are no explicit instructions to sanitize, validate, or filter the content retrieved from tickets or repository files before the implementation phase.
- [COMMAND_EXECUTION]: The skill utilizes standard Git commands to manage the development lifecycle.
- Evidence: The instructions explicitly direct the agent to use
git ls-remote,git fetch,git push, andgit rev-parseto synchronize with remote repositories and manage branches. These operations are core to the skill's functionality and are used within the scope of the target repository.
Audit Metadata