repo-research-analyst
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from repository files (README, ARCHITECTURE, CLAUDE.md, GitHub issues). It specifically instructs the agent to "Respect any CLAUDE.md or project-specific instructions found" without providing boundary markers or sanitization guidelines. An attacker who can influence the content of these files in a repository being analyzed could potentially influence the agent's behavior.
- Ingestion points: Processes external repository content including documentation files, issue templates, and issue history via
readandgreptools as described inSKILL.md. - Boundary markers: None present; the skill lacks instructions to treat retrieved content as data rather than instructions.
- Capability inventory: Includes file search (
glob,grep,ast-grep) and file reading (read) capabilities. - Sanitization: None present in the instructions.
Audit Metadata