feedback-application
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of external data.
- Ingestion points: The skill processes "reviewer comments," "PR review notes," and "list of changes requested by reviewers" as identified in the 'When to Use' and 'Systematic Workflow' sections of SKILL.md.
- Boundary markers: There are no explicit instructions for the agent to use XML tags, delimiters, or specific warnings to ignore embedded instructions within the feedback data.
- Capability inventory: The skill uses tools for reading and writing files (Edit, Write, Grep, Glob) and performs shell command execution (uv run ruff check).
- Sanitization: There is no mention of sanitizing, escaping, or validating the content of the external feedback before the agent acts upon it.
- [COMMAND_EXECUTION]: The skill explicitly instructs the agent to execute shell commands for validation.
- Evidence: The 'Validation' section in SKILL.md requires running
uv run ruff check. While ruff is a standard linting tool, this confirms the agent environment's ability to execute shell commands based on the skill's instructions.
Audit Metadata