absurd-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process arbitrary code provided in the $code-scope variable (Task 1, SKILL.md), which establishes a surface for indirect prompt injection if the analyzed code contains malicious instructions. The workflow mitigates this through fresh sub-agent delegation and task-specific constraints (Task 1, Constraint A) that limit inspection to the resolved scope. Task 4 (SKILL.md) identifies capabilities for the agent to 'research relevant sources' and execute 'project tests or measurements' based on the input code. The skill utilizes task boundaries and fingerprinting instead of explicit input sanitization or escaping to manage these inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 06:59 PM
Security Audit — agent-trust-hub — absurd-code-review