agent-task-relay
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process inbound findings, audit reports, and status responses from external agents or conversations, creating a surface for indirect prompt injection. \n
- Ingestion points: Processes user-mediated transfers of review findings, status responses, and external repository content as detailed in
SKILL.mdandreferences/inbound-findings.md. \n - Boundary markers: The skill contains explicit instructions to quote or delimit untrusted content to prevent it from being interpreted as instructions (
SKILL.md). \n - Capability inventory: The skill has the capability to draft working-tree changes (fixes) and manage dependency additions/updates in a repository context. \n
- Sanitization: The skill implements a robust security posture where external content cannot authorize actions or override policies; it mandates human confirmation gates for all mutations and dependency changes (
references/inbound-findings.mdandreferences/task-relays.md).
Audit Metadata