pr
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with untrusted data by analyzing repository diffs and files to generate documentation.
- Ingestion points: The agent is instructed in
SKILL.mdto read the actual diffs and changed files within the repository. - Boundary markers: No specific delimiters or boundary markers are defined to isolate the ingested code from the agent's internal instructions.
- Capability inventory: The skill performs file reading and repository inspection but does not utilize tools for network exfiltration or arbitrary command execution.
- Sanitization: There is no specific logic described to sanitize or filter potential prompt injection attempts hidden in code comments or diff metadata.
Audit Metadata