source-command-continue

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it is instructed to process untrusted data from the repository to determine its fixes.
  • Ingestion points: The agent is directed to read README files, main entry points, core flows, and scan for TODO, FIXME, and HACK strings within project files to identify work (SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters used to separate analyzed code/comments from the agent's operational instructions.
  • Capability inventory: The skill has high capabilities, specifically the mandate to 'Fix, don't report' and 'Implement solutions directly' (SKILL.md).
  • Sanitization: No sanitization or validation of the content discovered in the project files is mentioned before the agent implements changes based on that content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 05:12 PM
Security Audit — agent-trust-hub — source-command-continue