qa
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its core workflow. Ingestion points: The agent ingests untrusted user descriptions and codebase content (SKILL.md). Boundary markers: The instructions lack explicit delimiters or ignore directives for the ingested data. Capability inventory: The skill utilizes the gh tool for network-bound issue creation and spawns background agents for file system exploration. Sanitization: There is no evidence of sanitization or validation of the input before it is used to generate GitHub issue bodies or drive background exploration. Automation risk: The instruction to bypass user review before filing issues (gh issue create) increases the potential impact of processed malicious input.
Audit Metadata