alaga
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external inputs such as issue reports and diagnostic logs, which presents an attack surface for indirect prompt injection.\n
- Ingestion points: Data is ingested from issue reports and provider evidence in the intake and diagnosis phases (references/issue-intake.md, references/diagnosis.md).\n
- Boundary markers: The skill contains explicit instructions to treat retrieved content as evidence rather than instructions (references/issue-intake.md).\n
- Capability inventory: The agent can modify the filesystem, execute shell commands like git bisect, and use publication tools like seda-pr (SKILL.md, references/diagnosis-probes.md).\n
- Sanitization: The instructions recommend redacting secrets and sensitive payloads during diagnostic probes (references/diagnosis-probes.md).\n- [DYNAMIC_EXECUTION]: The instructions direct the agent to generate and execute custom scripts or codemods to perform code transformations and verify changes (SKILL.md).
Audit Metadata