perf-theory-gatherer
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from repository history and source code files.
- Ingestion points: The agent is instructed to "Review recent git history" and "Identify code paths" in SKILL.md. It also consumes instructions from a local file docs/perf-requirements.md.
- Boundary markers: The skill does not provide delimiters or instructions to the agent to treat content found in git logs or code as data rather than instructions.
- Capability inventory: Uses repository analysis tools such as grep and git history access to read file content.
- Sanitization: No sanitization or validation of the ingested repository content is specified to prevent malicious instructions in commits or comments from influencing agent behavior.
Audit Metadata