Security Best Practices

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and analyze external source code. Maliciously crafted comments or code patterns in the analyzed files could attempt to subvert the agent's analysis, hide vulnerabilities, or trick the agent into recommending insecure fixes.
  • Ingestion points: The skill processes user-provided source code, logs, and configuration files during security reviews (SKILL.md, review-playbook.md).
  • Boundary markers: Absent. The skill does not explicitly instruct the agent to use delimiters or ignore instructions embedded within the data being analyzed.
  • Capability inventory: The skill can propose code modifications (SKILL.md) and maintains a local findings log (memory-template.md).
  • Sanitization: Absent. No explicit sanitization or validation of the ingested code content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 10:45 AM
Security Audit — agent-trust-hub — Security Best Practices