source-review-technique

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for analyzing external source code. This creates a vulnerability surface where a malicious codebase could attempt to influence the agent's behavior through instructions hidden in code comments or strings. However, since the primary purpose of the skill is security auditing, this surface is inherent to its function.
  • Ingestion points: The agent is directed to read and traverse source files in SKILL.md (Sections 1 and 2).
  • Boundary markers: The skill does not provide specific instructions to the agent to distinguish between its own operational instructions and potentially malicious instructions embedded in the code being analyzed.
  • Capability inventory: The workflow involves file reading, structural search via tools like semgrep or ripgrep, and data-flow analysis.
  • Sanitization: There are no instructions for sanitizing or escaping the content of the analyzed source code before it is processed by the agent.
  • [COMMAND_EXECUTION]: The file references/bug-classes.md lists numerous sensitive functions such as eval(), system(), and subprocess.run(). These are provided strictly as search patterns for auditing purposes and are not executed by the skill instructions themselves.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — source-review-technique