load-mr-context

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses Model Context Protocol (MCP) tools (mcp__plugin_gitlab_gitlab__*) for all its operations, ensuring data access is mediated through an authorized and structured interface.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from GitLab Merge Requests.\n
  • Ingestion points: SKILL.md implementation steps 3a, 3b, and 3d (retrieving MR descriptions, diffs, and review notes).\n
  • Boundary markers: Absent; the skill does not instruct the agent to use specific delimiters or ignore instructions found within the retrieved MR data.\n
  • Capability inventory: The skill's capabilities are limited to reading GitLab metadata, viewing diffs, and checking pipeline statuses via MCP tools.\n
  • Sanitization: There is no explicit sanitization or filtering of the fetched external content before it is processed by the agent.\n- [SAFE]: The instruction to gather context 'silently' is used for concise UI presentation and does not represent an attempt to conceal malicious activity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 01:25 AM
Security Audit — agent-trust-hub — load-mr-context