no-comments
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted files and diffs, interpreting text within comments as logic for generating new code structures. 1. Ingestion points: The skill reads caller files and git diffs as its primary scope. 2. Boundary markers: Absent; there are no explicit delimiters to separate untrusted file content from the agent's instructions. 3. Capability inventory: The skill can spawn subagents (Task), perform symbolic analysis (/how, /why), and generate code designs (/architect). 4. Sanitization: The skill includes review logic to reject application-code edits and misstated findings, though it still relies on the model to interpret comment-based instructions for generating new tests or types.
- [COMMAND_EXECUTION]: The skill invokes internal platform tools including /how, /why, and /architect to perform code analysis and design tasks.
Audit Metadata