goodreview
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads uncommitted code which may contain malicious instructions designed to influence the agent's analysis.
- Ingestion points:
SKILL.mdusesgit diffand reads local file content to provide context to specialists. - Boundary markers: While the specialist briefs in
references/specialists.mdprovide role-specific context, the analyzed code snippets are not wrapped in delimiters that instruct the model to ignore embedded commands. - Capability inventory: The skill executes several
gitcommands via shell (SKILL.md) and calls external Codex MCP tools for synthesis. - Sanitization: There is no evidence of filtering or sanitizing the content of the analyzed files before processing.
Audit Metadata