soia-dev-fix-loop

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes findings from external sources and uses that data to perform reproduction steps involving shell commands.\n
  • Ingestion points: External findings data processed in the '1. 复现并规范化输入' section of SKILL.md.\n
  • Boundary markers: There are no explicit delimiters or instructions defined to isolate potentially malicious commands embedded in findings during the reproduction phase.\n
  • Capability inventory: The skill is designed to execute shell commands and scripts to reproduce identified issues (SKILL.md, Step 1).\n
  • Sanitization: While the skill recommends de-identifying sensitive user data for reporting, it lacks explicit sanitization for shell inputs derived from external findings.\n- [EXTERNAL_DOWNLOADS]: The documentation includes instructions to fetch and install supporting tools from the vendor's official GitHub repositories and package registries.\n
  • Evidence: Mentions of soia-team/soia-open-skills and soia-team/soia-open-dev-skills in the installation section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 07:59 AM
Security Audit — agent-trust-hub — soia-dev-fix-loop