fix-issue
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from issue discussions and pull request histories to guide code modifications and automated submissions.
- Ingestion points: External issue discussions and relevant PR history files referenced in the instructions.
- Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions within the ingested issue data.
- Capability inventory: The skill has the ability to execute Python tests, modify source code, and perform network operations to update or open pull requests.
- Sanitization: There are no documented steps for sanitizing or validating the contents of the processed issues before implementation.
Audit Metadata