skills/bholmesdev/skills/done/Gen Agent Trust Hub

done

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of natural language instructions and does not include any scripts, external downloads, or requests for sensitive information.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface: The skill instructs the agent to review uncommitted code, which is a source of untrusted data. This creates a surface where malicious instructions embedded in code comments could attempt to influence the agent's behavior.
  • Ingestion points: Uncommitted code in the repository (logic for reviewing uncommitted changes).
  • Boundary markers: No delimiters or specific 'ignore embedded instructions' warnings are present.
  • Capability inventory: git commit, git rebase, git merge, worktree cleanup, and GitHub issue updates.
  • Sanitization: No validation or sanitization of the code content is specified before the review process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:45 PM
Security Audit — agent-trust-hub — done