wa-review
Fail
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: CRITICALPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: Analysis of the skill's instructions, logic, and reference files confirms that they are entirely consistent with its stated purpose of performing architectural assessments. No malicious code, obfuscation, or persistence mechanisms were detected.
- [EXTERNAL_DOWNLOADS]: The skill contains references to technical documentation and reference architectures hosted on domains including 'aws.amazon.com' and 'aws-samples.github.io'. In accordance with the Trust Scope Rule, these are identified as verified resources from a trusted organization and do not contribute to risk.
- [PROMPT_INJECTION]: The skill's ingestion of external codebase artifacts and architecture descriptions represents an indirect prompt injection surface. This is evaluated as a low-risk inherent characteristic of the tool's analyzer functionality. Evidence chain: 1. Ingestion points: 'SKILL.md' (Step 1 and Step 4) and 'SKILL-devops-agent.md' (Step 1) read user-provided code and descriptions into context. 2. Boundary markers: Absent; the skill does not use specific delimiters for ingested content. 3. Capability inventory: The skill uses 'Read', 'Task' (subagent dispatch), and 'Write' (emits 'wa-review.json') in 'SKILL.md'. 4. Sanitization: Absent; content is interpolated into subagent prompts without prior filtering.
Recommendations
- CRITICAL: 6 file(s) identified as malware by FileRep - DO NOT USE
- Contains 6 malicious URL(s) - DO NOT USE
Audit Metadata