application-security-requirements
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, exfiltration code, or hardcoded credentials were found in the skill files. The guidelines are strictly defensive.
- [NO_CODE]: The skill consists only of Markdown files and does not include any scripts or binaries.
- [PROMPT_INJECTION]: The skill's role in auditing code diffs and CMS-authored content creates an indirect prompt injection surface. 1. Ingestion points: Code snippets and git diffs provided for analysis. 2. Boundary markers: No specific delimiters are mandated in the instructions to isolate untrusted inputs. 3. Capability inventory: The auditing agent typically possesses read access to the local codebase. 4. Sanitization: The skill does not define methods for sanitizing or escaping the content being audited.
Audit Metadata