work
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface as it is designed to ingest and analyze untrusted data like source code and repository artifacts during its auditing and cleanup processes.\n
- Ingestion points: The audit and clean modes (
skills/work-audit/SKILL.md,skills/work-clean/SKILL.md) read working trees, commits, branches, and runtime flows.\n - Boundary markers: The instructions do not define specific delimiting patterns or ignore-instructions for the external data being analyzed.\n
- Capability inventory: The project initialization mode (
skills/work-init/SKILL.md) is authorized to create files, install packages, and execute local shell commands for builds, tests, and starting applications.\n - Sanitization: No explicit sanitization or filtering of external content is specified beyond the requirement for evidence-based verification.
Audit Metadata