detect-spam

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from feature request titles and descriptions fetched via the wccom-feature-requests-list tool.
  • Ingestion points: Feature request data is ingested in Step 2 and analyzed in Step 3 of SKILL.md.
  • Boundary markers: No specific delimiters or safety instructions are used when interpolating the feature request content into the analysis prompt.
  • Capability inventory: The skill possesses the capability to update the status of feature requests using the wccom-feature-requests-update-status tool.
  • Sanitization: No evidence of sanitization or filtering of the incoming user-generated content is present.
  • Mitigation: The risk is mitigated by a mandatory human-in-the-loop confirmation (Step 5), where the user must manually select which requests to mark as spam before any changes are applied.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 03:47 AM
Security Audit — agent-trust-hub — detect-spam