skills/sones3/skills/to-prd/Gen Agent Trust Hub

to-prd

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it incorporates external repository data and conversation history into its output.\n
  • Ingestion points: Repository file system (via exploration) and conversation context.\n
  • Capability inventory: Repository exploration (file read) and GitHub issue submission (network write).\n
  • Boundary markers: None identified in the skill instructions.\n
  • Sanitization: No explicit instructions provided for sanitizing or escaping ingested content before submission to GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 04:26 PM
Security Audit — agent-trust-hub — to-prd