loop
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill initiates network operations to clone or browse repositories using URLs provided in the topology.md configuration file. Evidence: Step 3 instructions mention using companion.url for cloning or browsing when local paths are missing.
- [PROMPT_INJECTION]: The skill processes data from multiple configuration files and external companion repositories that could be used for indirect prompt injection.
- Ingestion points: vcs.md, stack.md, quality-gates.md, topology.md, and external companion repository content.
- Boundary markers: The skill lacks specific delimiters or warnings to ignore instructions within ingested data.
- Capability inventory: The skill dispatches agents (builder, checker), creates git branches, and runs verification tools.
- Sanitization: No evidence of validation or filtering for data read from configuration files or external repositories.
Audit Metadata