meta-migration-assistant
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill uses internal control directives like 'Task lock' and 'Hard override' to ensure the agent prioritizes the user's specific migration goal over potentially conflicting data from tools or classifiers.
- [COMMAND_EXECUTION]: The skill utilizes git-diff to examine the repository's state, providing context for the migration plan.
- [EXTERNAL_DOWNLOADS]: The skill fetches content from external search engines (DuckDuckGo, Brave) to identify authoritative migration documentation.
- [PROMPT_INJECTION]: An indirect prompt injection surface exists through the ingestion of external search results and repository data. The skill mitigates this by using XML escaping on user input and including explicit instructions that forbid the generation of destructive or file-modifying commands in the output.
Audit Metadata