cognitive-load
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill is entirely prompt-based, containing only Markdown documentation and natural language instructions. It does not include any scripts (Python, JavaScript, shell) or binaries, precluding risks related to local execution, privilege escalation, or persistence.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to analyze external code, which constitutes a surface for indirect prompt injection if the ingested code contains instructions intended to manipulate the agent. However, the risk is mitigated by the lack of actionable capabilities.
- Ingestion points: Code provided by the user to the agent for review, as described in
SKILL.md. - Boundary markers: Absent; there are no specific delimiters or instructions for the agent to ignore embedded commands within the analyzed code.
- Capability inventory: None. The skill is limited to generating text-based review summaries and does not have access to file-system writes, network operations, or command execution tools.
- Sanitization: None present in the instructions.
Audit Metadata