workflow
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to autonomously ingest and act on external data which may contain untrusted content.
- Ingestion points: External bug reports, system logs, and failing CI test output are processed as per the 'Autonomous Bug Fixing' section in SKILL.md.
- Boundary markers: The instructions do not define specific delimiters or security guardrails (e.g., 'ignore embedded instructions') for handling data from these external sources.
- Capability inventory: The agent is directed to modify project files (bug fixes), write to management files (tasks/todo.md, tasks/lessons.md), and execute tests based on the processed inputs, as described in SKILL.md.
- Sanitization: The skill lacks explicit instructions for sanitizing or validating the content extracted from external bug reports or logs.
Audit Metadata