decision
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to analyze external data from sources such as issue and PR history, research, and project documentation. This creates a surface for indirect prompt injection where instructions embedded in these external files could potentially influence the agent's behavior.
- Ingestion points: External artifacts like decision records, research, requirements, issue/PR history, and design-system documentation as specified in SKILL.md.
- Boundary markers: The skill does not provide specific instructions to delimit or ignore instructions found within these external sources.
- Capability inventory: The skill does not define or use high-risk tools such as network access or arbitrary command execution.
- Sanitization: No sanitization or validation of the ingested external content is mentioned.
Audit Metadata