bug-retro

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows professional engineering practices for failure analysis. It contains no network exfiltration patterns, hardcoded credentials, or remote code execution vectors. The configuration restricts the agent to explicit invocation only.
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface due to its primary function of analyzing untrusted failure logs and source code.
  • Ingestion points: Ingests failing test results, error logs, and project source files provided in the conversation context.
  • Boundary markers: The skill does not employ specific delimiters or boundary instructions to isolate external data from its internal logic.
  • Capability inventory: The skill is capable of performing file edits and version control operations (git stage/commit/push) if explicitly requested by the user.
  • Sanitization: There are no instructions for sanitizing or escaping the content of failure logs or code files before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 10:09 AM
Security Audit — agent-trust-hub — bug-retro