merge-readiness

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted local repository data, including Git diffs and file artifacts, to generate reports and quiz questions. This constitutes an indirect prompt injection surface where a deceptive code change could attempt to influence the summary or questions to hide risks. \n
  • Ingestion points: Phase 0 evidence collection (Local Git diff, changed files, test/QA/verification artifacts). \n
  • Boundary markers: None specified in the instructions to differentiate untrusted code content from the agent's instructions. \n
  • Capability inventory: The skill uses specific tools (merge_readiness_start, merge_readiness_set_content, merge_readiness_report) to manage session state and render documentation. \n
  • Sanitization: There is no evidence of sanitization or filtering of the input diff data before it is processed by the AI for content generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 10:55 AM
Security Audit — agent-trust-hub — merge-readiness