supervisor-review-queue
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted content from student drafts and the review queue YAML without protective boundaries.\n
- Ingestion points: The queue file
references/review-queue.yamland the external document files specified by thecontent_pathproperty.\n - Boundary markers: The instructions do not define delimiters or specific warnings to isolate student-provided content from agent commands.\n
- Capability inventory: Includes reading application configuration and draft files, and writing status updates and logs to the local filesystem.\n
- Sanitization: No validation or sanitization is performed on the ingested content before it is processed by the agent.
Audit Metadata