style-guide-review

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and process untrusted data from pull request diffs. This represents a potential attack surface where instructions embedded in the documentation could attempt to influence the agent's behavior.
  • Ingestion points: Untrusted content enters the agent's context through the prompt (added lines) and via the read_repo_file tool.
  • Boundary markers: The SKILL.md includes strong directives to minimize reasoning, avoid prose output, and only perform mechanical pattern matching, which serve as functional boundaries.
  • Capability inventory: The skill uses read_repo_file to access repository content, read_skill_resource to access style guide rules, and submit_style_guide to return its results. It does not have general shell execution or network access capabilities.
  • Sanitization: The skill focuses on specific line-by-line matches against known rule sets, which naturally limits the impact of arbitrary content in the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:03 PM
Security Audit — agent-trust-hub — style-guide-review