bug-report

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and process untrusted data from the codebase and user descriptions.
  • Ingestion points: Codebase files (accessed via Read, Glob, Grep) and user-provided bug descriptions.
  • Boundary markers: Absent. The instructions do not define delimiters or provide specific warnings to ignore instructions found within the processed files.
  • Capability inventory: The skill utilizes Read, Glob, Grep, and Write tools, allowing it to both read from and modify the filesystem (e.g., to write bug reports).
  • Sanitization: Absent. There is no logic provided to sanitize or validate the content of the files being analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — bug-report