skills/ycs77/skills/triage/Gen Agent Trust Hub

triage

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides clear instructions for repository triage, including safety measures like mandatory AI disclaimers and maintainer verification steps. No malicious behaviors or data exfiltration patterns were identified.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub issues and pull request diffs, and includes capabilities to execute tests or commands to verify PRs. While this presents an attack surface for indirect prompt injection or code execution from malicious PRs, it is an inherent part of the skill's primary verification function. 1. Ingestion points: GitHub issue bodies and PR comments (SKILL.md). 2. Boundary markers: AI-generated disclaimer requirement for all generated comments. 3. Capability inventory: Filesystem access (codebase), command execution (verification tests), and issue tracker interaction (labels/comments). 4. Sanitization: Not explicitly specified in instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 08:11 AM
Security Audit — agent-trust-hub — triage