reviewing-project-guidance
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external
CLAUDE.mdfiles which may contain malicious instructions designed to influence agent behavior. - Ingestion points: Processes content from
CLAUDE.mdfiles located at project roots or in.claude/directories (SKILL.md). - Boundary markers: The skill includes explicit directives to treat the reviewed material as data rather than instructions and provides a strong warning to disregard any authority claims found within the text (SKILL.md).
- Capability inventory: Tool access is strictly limited to read-only operations including
Read,Grep, andGlob(SKILL.md). - Sanitization: The instructions direct the agent to quote, classify, and report on findings rather than executing instructions found in the data (SKILL.md).
Audit Metadata