source-review-technique
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for analyzing external source code. This creates a vulnerability surface where a malicious codebase could attempt to influence the agent's behavior through instructions hidden in code comments or strings. However, since the primary purpose of the skill is security auditing, this surface is inherent to its function.
- Ingestion points: The agent is directed to read and traverse source files in
SKILL.md(Sections 1 and 2). - Boundary markers: The skill does not provide specific instructions to the agent to distinguish between its own operational instructions and potentially malicious instructions embedded in the code being analyzed.
- Capability inventory: The workflow involves file reading, structural search via tools like
semgreporripgrep, and data-flow analysis. - Sanitization: There are no instructions for sanitizing or escaping the content of the analyzed source code before it is processed by the agent.
- [COMMAND_EXECUTION]: The file
references/bug-classes.mdlists numerous sensitive functions such aseval(),system(), andsubprocess.run(). These are provided strictly as search patterns for auditing purposes and are not executed by the skill instructions themselves.
Audit Metadata