feedback-application

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of external data.
  • Ingestion points: The skill processes "reviewer comments," "PR review notes," and "list of changes requested by reviewers" as identified in the 'When to Use' and 'Systematic Workflow' sections of SKILL.md.
  • Boundary markers: There are no explicit instructions for the agent to use XML tags, delimiters, or specific warnings to ignore embedded instructions within the feedback data.
  • Capability inventory: The skill uses tools for reading and writing files (Edit, Write, Grep, Glob) and performs shell command execution (uv run ruff check).
  • Sanitization: There is no mention of sanitizing, escaping, or validating the content of the external feedback before the agent acts upon it.
  • [COMMAND_EXECUTION]: The skill explicitly instructs the agent to execute shell commands for validation.
  • Evidence: The 'Validation' section in SKILL.md requires running uv run ruff check. While ruff is a standard linting tool, this confirms the agent environment's ability to execute shell commands based on the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — feedback-application