gpt-orchestration-build
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as audits, issue sets, and test reports to drive code implementation. \n
- Ingestion points: Identified in
SKILL.md(audit, issue set, review, failing-test report). \n - Boundary markers: The skill does not specify explicit delimiters or boundary markers to separate external data from system instructions. \n
- Capability inventory: The skill performs repository reads, code implementation, and execution of verification checks. \n
- Sanitization: The skill mandates validation of findings against source code and documentation, but lacks specific escaping or instruction-ignoring delimiters for the processed text.
Audit Metadata