total-review
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests findings from external reviewer outputs (fable-review and gpt-review) which are then used to drive automated code fixes and git operations.
- Ingestion points: Step 3 of the workflow reads the output reports generated by the sub-agent threads.
- Boundary markers: The skill lacks explicit delimiters or instructions to ignore potential instructions embedded within the review reports.
- Capability inventory: The skill possesses file-write capabilities for fixing code and network capabilities for pushing commits to GitHub.
- Sanitization: A manual triage step is included to filter findings, and a mandatory user approval step is required before any actions are taken, which serves as a primary security control.
Audit Metadata