vercel-agent
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill describes a workflow for analyzing Pull Requests and PR comments, which are external data sources. This presents a potential surface for indirect prompt injection where external content could influence agent behavior.
- Ingestion points: The agent analyzes Pull Request content and mentions in comments as described in SKILL.md.
- Boundary markers: No specific delimiters for separating system instructions from untrusted data are defined in the provided documentation.
- Capability inventory: The documentation mentions the agent's ability to generate patches, install SDKs, and create Pull Requests.
- Sanitization: No specific filtering or sanitization procedures for ingested content are detailed in the provided files.
Audit Metadata