document-review

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) due to the way it processes untrusted document content.
  • Ingestion points: In Phase 1, the skill reads document content from user-specified paths or using glob patterns in docs/brainstorms/ and docs/plans/.
  • Boundary markers: The document content is interpolated into the {document_content} variable within a subagent template in Phase 2. There is no mention of using specific delimiters or 'ignore instruction' guardrails to prevent the agent from obeying instructions embedded within the analyzed document.
  • Capability inventory: The skill possesses significant capabilities, most notably the Edit tool used in Phase 4. In headless mode, the skill applies 'auto' fixes silently without user approval, which increases the risk if the logic is manipulated by an injection.
  • Sanitization: There is no evidence of sanitization, escaping, or validation performed on the ingested document content before it is passed to the reviewer personas.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 06:41 AM
Security Audit — agent-trust-hub — document-review