review-me
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze data from the repository and current conversation, creating a surface for indirect prompt injection.
- Ingestion points: Data enters the context from the repository, files, and conversation history as specified in SKILL.md (Step 1).
- Boundary markers: There are no instructions for the agent to use specific delimiters or to disregard potential instructions embedded within the files being reviewed.
- Capability inventory: The skill utilizes file reading and environment inspection, but is constrained by disable-model-invocation: true in the frontmatter, limiting unauthorized tool use.
- Sanitization: The instructions do not define methods for sanitizing or escaping the content retrieved from external files.
Audit Metadata