application-security

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown-based instructions and guidelines for an AI agent to follow during code writing or review tasks. No executable scripts, binaries, or automated tool configurations are included.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted code and diffs, which is an inherent attack surface for indirect prompt injection. \n
  • Ingestion points: User-provided code snippets and diffs within the review process.\n
  • Boundary markers: The instructions do not define specific delimiters for separating untrusted code from agent instructions.\n
  • Capability inventory: The skill does not invoke specific tools, subprocesses, or network operations, operating within the agent's baseline capabilities.\n
  • Sanitization: No explicit input sanitization or filtering logic is provided for the content being reviewed.\n- [SAFE]: No obfuscation, credential hardcoding, or data exfiltration attempts were identified. All external references are to standard documentation such as RFC 2119.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 01:16 AM
Security Audit — agent-trust-hub — application-security