opsx-android-bug
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it processes untrusted data from user-supplied bug reports to determine the parameters for tool execution.
- Ingestion points: The bug description or report provided as a command-line argument to the
/opsx:android-bugslash-command. - Boundary markers: The skill definition lacks explicit delimiters or instructions for the agent to ignore or neutralize instructions embedded within the user-provided bug report.
- Capability inventory: The agent is instructed to use the
codegraph exploretool and theopenspecCLI to create changes, designs, and tasks based on the input. - Sanitization: There is no evidence of input validation, sanitization, or escaping of the user-provided content before it is processed by the agent's workflow.
Audit Metadata