skills/agoodway/goodskills/goodreview/Gen Agent Trust Hub

goodreview

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads uncommitted code which may contain malicious instructions designed to influence the agent's analysis.
  • Ingestion points: SKILL.md uses git diff and reads local file content to provide context to specialists.
  • Boundary markers: While the specialist briefs in references/specialists.md provide role-specific context, the analyzed code snippets are not wrapped in delimiters that instruct the model to ignore embedded commands.
  • Capability inventory: The skill executes several git commands via shell (SKILL.md) and calls external Codex MCP tools for synthesis.
  • Sanitization: There is no evidence of filtering or sanitizing the content of the analyzed files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 10:09 AM
Security Audit — agent-trust-hub — goodreview