rightcode-triage

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill authorizes the agent to trace code and run commands or tests to verify and reproduce bugs reported in issues during the triage workflow.
  • [SAFE]: The skill processes untrusted content from issue trackers, creating an indirect prompt injection surface. (1) Ingestion points: Issue bodies and comments read in SKILL.md. (2) Boundary markers: Missing specific instructions to ignore embedded commands. (3) Capability inventory: Command execution for reproduction and API/file writes for triage notes and out-of-scope records. (4) Sanitization: None specified. The risk is mitigated by the workflow requiring maintainer confirmation for most actions.
  • [SAFE]: All AI-generated output is required to carry a disclaimer, and no attempts at obfuscation or unauthorized persistence were identified.
  • [SAFE]: The skill's access to the codebase and issue tracker is limited to the scope necessary for triaging and documenting issue status.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 04:43 AM
Security Audit — agent-trust-hub — rightcode-triage