loop-fixer
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it implements fixes based on instructions from external Evaluation Reports. If these reports contain malicious instructions, the agent could perform unintended code modifications.
- Ingestion points: Evaluation reports from loop-plan-evaluator or loop-execution-evaluator (SKILL.md).
- Boundary markers: Absent; no specific delimiters or ignore-instructions are defined for parsed report content.
- Capability inventory: Source code modification (Workflow step 3) and git commit operations (Workflow step 3).
- Sanitization: Absent; the workflow does not include validation or sanitization of the evaluation instructions.
Audit Metadata