agent-task-relay

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process inbound findings, audit reports, and status responses from external agents or conversations, creating a surface for indirect prompt injection. \n
  • Ingestion points: Processes user-mediated transfers of review findings, status responses, and external repository content as detailed in SKILL.md and references/inbound-findings.md. \n
  • Boundary markers: The skill contains explicit instructions to quote or delimit untrusted content to prevent it from being interpreted as instructions (SKILL.md). \n
  • Capability inventory: The skill has the capability to draft working-tree changes (fixes) and manage dependency additions/updates in a repository context. \n
  • Sanitization: The skill implements a robust security posture where external content cannot authorize actions or override policies; it mandates human confirmation gates for all mutations and dependency changes (references/inbound-findings.md and references/task-relays.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 01:46 PM
Security Audit — agent-trust-hub — agent-task-relay