source-command-continue
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it is instructed to process untrusted data from the repository to determine its fixes.
- Ingestion points: The agent is directed to read README files, main entry points, core flows, and scan for TODO, FIXME, and HACK strings within project files to identify work (SKILL.md).
- Boundary markers: There are no explicit instructions or delimiters used to separate analyzed code/comments from the agent's operational instructions.
- Capability inventory: The skill has high capabilities, specifically the mandate to 'Fix, don't report' and 'Implement solutions directly' (SKILL.md).
- Sanitization: No sanitization or validation of the content discovered in the project files is mentioned before the agent implements changes based on that content.
Audit Metadata