triage
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because its core function involves ingesting and processing untrusted data from external sources.
- Ingestion points: The agent is instructed to read issue bodies, comments, labels, and pull request diffs (
SKILL.md, Section 1 under 'Triage one item'). - Boundary markers: No explicit delimiters or instructions are provided to the agent to distinguish between its system instructions and potentially malicious instructions embedded in the issue tracker content.
- Capability inventory: The agent has the ability to mutate the tracker (labels, comments, state), interact with other tools (
work-github-issue,documenting-work), and execute arbitrary commands or checks for verification. - Sanitization: There is no mention of sanitizing or filtering the content ingested from the tracker before it is processed or used in decision-making.
- [COMMAND_EXECUTION]: The skill instructions require the agent to execute commands or code derived from or inspired by untrusted external reports.
- Evidence: In
SKILL.md(Section 3 'Verify the claim'), the agent is told to "reproduce it from the reported steps" and "run the narrowest relevant checks" for pull requests. While the instructions advise using a disposable or non-production environment, executing logic provided by an untrusted external reporter presents a risk of command injection or malicious code execution if the environment is not perfectly isolated.
Audit Metadata