vp-issue-investigator

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior during the investigation or filing process.
  • Ingestion points: The skill ingests suspected software problems, bug reports, regressions, and repository scan results (SKILL.md).
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded commands within the ingested content.
  • Capability inventory: The skill has the capability to file issues in internal or third-party trackers and upload local files (screenshots, recordings, diagrams) using the vp-github skill (SKILL.md).
  • Sanitization: No specific sanitization or validation logic is defined to filter potentially malicious content from ingested reports before they are processed or submitted to external trackers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:24 AM
Security Audit — agent-trust-hub — vp-issue-investigator