rightcode-triage
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill authorizes the agent to trace code and run commands or tests to verify and reproduce bugs reported in issues during the triage workflow.
- [SAFE]: The skill processes untrusted content from issue trackers, creating an indirect prompt injection surface. (1) Ingestion points: Issue bodies and comments read in SKILL.md. (2) Boundary markers: Missing specific instructions to ignore embedded commands. (3) Capability inventory: Command execution for reproduction and API/file writes for triage notes and out-of-scope records. (4) Sanitization: None specified. The risk is mitigated by the workflow requiring maintainer confirmation for most actions.
- [SAFE]: All AI-generated output is required to carry a disclaimer, and no attempts at obfuscation or unauthorized persistence were identified.
- [SAFE]: The skill's access to the codebase and issue tracker is limited to the scope necessary for triaging and documenting issue status.
Audit Metadata