closed-loop-delivery

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon external data from pull request comments and reviews.
  • Ingestion points: Pull request comments and reviews are fetched during the Review Loop phase (SKILL.md).
  • Boundary markers: No explicit delimiters or boundary markers are defined for the fetched external content.
  • Capability inventory: The skill uses file-writing tools for code changes and command execution for running tests and performing deployments.
  • Sanitization: No specific sanitization of PR feedback is mentioned; however, the skill mandates human-in-the-loop gates for production deployments, destructive operations, and security posture changes, preventing automated escalation of malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 12:18 PM
Security Audit — agent-trust-hub — closed-loop-delivery