triage

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a logical triage state machine for managing project issues and pull requests. It provides clear documentation on writing agent briefs and maintaining a knowledge base of out-of-scope features.
  • [DATA_EXPOSURE_&_EXFILTRATION]: The skill requires access to the project's issue tracker and codebase to perform its primary function of triage. However, it does not include hardcoded credentials or instructions to send sensitive data to external, non-whitelisted domains. All activity is directed toward the internal project environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from the issue tracker (issue bodies, comments, PR diffs). It mitigates this risk by requiring human-in-the-loop confirmation for state transitions and providing specific templates (like the Agent Brief) that set clear boundaries for downstream agents. All reported findings for this category are considered low risk due to the instructional nature of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:01 PM
Security Audit — agent-trust-hub — triage