tailrocks-improve-reconcile
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external repositories to reconcile plan statuses. While it includes instructions to ignore roadmap items and follow strict reconciliation logic, the ingestion of untrusted repository content (plan bodies, evidence, and paths) creates a surface for indirect prompt injection where malicious instructions embedded in the repository could attempt to influence the agent's reasoning during the reconciliation process.
Audit Metadata