code-tour

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: Analyzed the skill for indirect prompt injection surfaces where codebase content could influence agent behavior. Ingestion points: Source code files, README, and configuration files. Boundary markers: None explicitly defined. Capability inventory: Capability to write JSON files to the .tours/ directory. Sanitization: No specific validation of ingested content.
  • [SAFE]: The skill uses a JSON schema from a well-known service domain for validating output formatting.
  • [SAFE]: All file operations are localized to the repository's .tours directory for documentation purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 04:00 AM
Security Audit — agent-trust-hub — code-tour