retrospective-codify
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from external sources.
- Ingestion points: The workflow processes content from PR review comments, CI failure analysis, bug reports, and user corrections (SKILL.md).
- Boundary markers: There are no explicit instructions or delimiters provided to the agent to disregard instructions that might be embedded within the source feedback.
- Capability inventory: The agent possesses file system capabilities to read and write to the project feedback ledger (ledger/review-feedback.md).
- Sanitization: While the skill instructs the agent not to store secrets or private data, it lacks specific sanitization logic to neutralize potential injection attempts within the feedback text itself.
Audit Metadata