skills/rca32/skills/triage/Gen Agent Trust Hub

triage

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because its core function involves ingesting and processing untrusted data from external sources.
  • Ingestion points: The agent is instructed to read issue bodies, comments, labels, and pull request diffs (SKILL.md, Section 1 under 'Triage one item').
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to distinguish between its system instructions and potentially malicious instructions embedded in the issue tracker content.
  • Capability inventory: The agent has the ability to mutate the tracker (labels, comments, state), interact with other tools (work-github-issue, documenting-work), and execute arbitrary commands or checks for verification.
  • Sanitization: There is no mention of sanitizing or filtering the content ingested from the tracker before it is processed or used in decision-making.
  • [COMMAND_EXECUTION]: The skill instructions require the agent to execute commands or code derived from or inspired by untrusted external reports.
  • Evidence: In SKILL.md (Section 3 'Verify the claim'), the agent is told to "reproduce it from the reported steps" and "run the narrowest relevant checks" for pull requests. While the instructions advise using a disposable or non-production environment, executing logic provided by an untrusted external reporter presents a risk of command injection or malicious code execution if the environment is not perfectly isolated.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 07:38 AM
Security Audit — agent-trust-hub — triage