human-review
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted repository data, constituting an indirect prompt injection surface.
- Ingestion points: Ingests repository diffs, specifications, and project instructions as defined in
SKILL.md. - Boundary markers: Lacks explicit text delimiters for untrusted content, using logical verification steps instead.
- Capability inventory: Read-access to repository files, write-access for temporary artifacts, and the ability to serve/open HTML files.
- Sanitization: Instructions mandate the redaction of secrets and personal data from the evidence.
Audit Metadata