skills/davidondrej/skills/gpt-review/Gen Agent Trust Hub

gpt-review

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a workflow for indirect prompt injection by processing untrusted data (the user's code) and requiring the output to be displayed to the user without modification.
  • Ingestion points: The skill ingests the user's "current work" (source code or documentation) to be reviewed by a subagent.
  • Boundary markers: There are no instructions provided to the agent to use delimiters or to treat the ingested code as potentially containing instructions (e.g., instructions to the reviewer model to hide malicious content or leak information).
  • Capability inventory: The skill utilizes subagent invocation (model invocation) and reports findings directly to the user's terminal.
  • Sanitization: The instructions explicitly forbid sanitization or modification of the output, stating: "show the user his exact response in full. Do not rewrite it. Do not update it."
  • [PROMPT_INJECTION]: The metadata and instructions refer to a non-existent model ("GPT 5.6 Sol Max"). While likely a stylistic choice, using fictional model names in instructions can lead to unpredictable agent behavior or user confusion regarding the actual security and capabilities of the underlying model.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 03:51 AM
Security Audit — agent-trust-hub — gpt-review