deslop
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of code diffs, which creates a potential surface for indirect prompt injection through malicious comments or identifiers.
- Ingestion points: Reads code diffs comparing current branch against
main(SKILL.md). - Boundary markers: None provided; the skill does not include specific delimiters or instructions to ignore embedded commands within the code being analyzed.
- Capability inventory: The skill is intended to perform file modifications to remove "slop" and simplifies code structure.
- Sanitization: No explicit sanitization or validation of the input code content is mentioned.
Audit Metadata