skills/cursor/plugins/deslop/Gen Agent Trust Hub

deslop

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of code diffs, which creates a potential surface for indirect prompt injection through malicious comments or identifiers.
  • Ingestion points: Reads code diffs comparing current branch against main (SKILL.md).
  • Boundary markers: None provided; the skill does not include specific delimiters or instructions to ignore embedded commands within the code being analyzed.
  • Capability inventory: The skill is intended to perform file modifications to remove "slop" and simplifies code structure.
  • Sanitization: No explicit sanitization or validation of the input code content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:33 AM
Security Audit — agent-trust-hub — deslop