qa-hunt

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill establishes a structured process for hunting bugs in live systems. Its instructions to 'sweep' data and 'verify before you file' are standard QA best practices and align with the skill's stated purpose.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from production databases and source code, which represents an indirect prompt injection surface. The risk is mitigated by the skill's requirement for cross-verification against multiple sources (code, database, and UI).
  • Ingestion points: Production data rows, codebase comments/content, and rendered application pages (SKILL.md).
  • Boundary markers: No specific delimiters or 'ignore embedded instructions' warnings are provided for the data being analyzed.
  • Capability inventory: The agent is instructed to read code, query production data, and interact with issue trackers like GitHub to file reports (SKILL.md).
  • Sanitization: The skill does not provide specific instructions for sanitizing or escaping the untrusted data before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 08:24 AM
Security Audit — agent-trust-hub — qa-hunt