Auditing Security
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to audit external codebases, which are untrusted ingestion points that could contain malicious instructions.\n
- Ingestion points: External codebase to audit,
docs/system-design.md,docs/api-contracts.yaml, and feature implementation markdown files specified in SKILL.md.\n - Boundary markers: The instructions lack explicit boundary markers or directions for the agent to ignore potentially malicious embedded prompts within the files being audited.\n
- Capability inventory: The skill involves the analysis of code and mentions using audit tools like
npm audit, although no specific tool permissions are granted in the frontmatter.\n - Sanitization: There is no evidence of sanitization or input validation for the data ingested during the audit process.\n- [NO_CODE]: The skill is purely instructional markdown and does not distribute any executable scripts or binaries.
Audit Metadata