curate-skill-repository
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted content from pull requests, proposals, and third-party skill packages to determine repository actions.\n
- Ingestion points: The agent is instructed to inventory and inspect 'installable packages', 'active proposals', and 'closed-unmerged sources' (references/repository-curation-patterns.md).\n
- Boundary markers: No delimiters or protective instructions are present to prevent the agent from executing instructions found within the curated data.\n
- Capability inventory: The skill grants the agent the ability to 'Rewrite', 'Archive', 'Transfer', and 'Absorb' content based on its analysis of external data.\n
- Sanitization: The process lacks validation or sanitization mechanisms for the data being ingested.
Audit Metadata