soia-dev-fix-loop
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes findings from external sources and uses that data to perform reproduction steps involving shell commands.\n
- Ingestion points: External findings data processed in the '1. 复现并规范化输入' section of SKILL.md.\n
- Boundary markers: There are no explicit delimiters or instructions defined to isolate potentially malicious commands embedded in findings during the reproduction phase.\n
- Capability inventory: The skill is designed to execute shell commands and scripts to reproduce identified issues (SKILL.md, Step 1).\n
- Sanitization: While the skill recommends de-identifying sensitive user data for reporting, it lacks explicit sanitization for shell inputs derived from external findings.\n- [EXTERNAL_DOWNLOADS]: The documentation includes instructions to fetch and install supporting tools from the vendor's official GitHub repositories and package registries.\n
- Evidence: Mentions of
soia-team/soia-open-skillsandsoia-team/soia-open-dev-skillsin the installation section of SKILL.md.
Audit Metadata