post-mortem
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources such as debugging ledgers and issue trackers, creating a surface for indirect prompt injection if the processed data contains malicious instructions.
- Ingestion points: The skill pulls information from the
systematic-debugbreadcrumb ledger, PR descriptions, and issue tracker comments (JIRA, GitHub, Linear). - Boundary markers: The skill does not define explicit delimiters for incoming data, though it requires human confirmation before external posting.
- Capability inventory: The skill uses
ReadandWritetools and has the capability to transmit data to external issue trackers. - Sanitization: The instructions do not specify sanitization or filtering for the external ledger data.
Audit Metadata