repo-research-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from repository files (README, ARCHITECTURE, CLAUDE.md, GitHub issues). It specifically instructs the agent to "Respect any CLAUDE.md or project-specific instructions found" without providing boundary markers or sanitization guidelines. An attacker who can influence the content of these files in a repository being analyzed could potentially influence the agent's behavior.
  • Ingestion points: Processes external repository content including documentation files, issue templates, and issue history via read and grep tools as described in SKILL.md.
  • Boundary markers: None present; the skill lacks instructions to treat retrieved content as data rather than instructions.
  • Capability inventory: Includes file search (glob, grep, ast-grep) and file reading (read) capabilities.
  • Sanitization: None present in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 06:49 AM
Security Audit — agent-trust-hub — repo-research-analyst