supervisor-review-queue

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted content from student drafts and the review queue YAML without protective boundaries.\n
  • Ingestion points: The queue file references/review-queue.yaml and the external document files specified by the content_path property.\n
  • Boundary markers: The instructions do not define delimiters or specific warnings to isolate student-provided content from agent commands.\n
  • Capability inventory: Includes reading application configuration and draft files, and writing status updates and logs to the local filesystem.\n
  • Sanitization: No validation or sanitization is performed on the ingested content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:59 PM
Security Audit — agent-trust-hub — supervisor-review-queue