review-implement
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted user data from the spec input and uses it to drive autonomous actions. Ingestion points: User-provided specifications via the $ARGUMENTS variable. Boundary markers: None identified. The input is not wrapped in protective delimiters or accompanied by instructions to ignore embedded commands. Capability inventory: The skill has extensive capabilities including file modification, PR creation, and running build/test commands. Sanitization: No sanitization or validation of the input specification is mentioned before it is used to guide the implementation.
Audit Metadata