krt-security-sentinel
Pass
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted content like pull request diffs, source code files, and work packages as part of its auditing workflow.
- Ingestion points: Processes work packages, file diffs, and repository source code in SKILL.md Step 2.
- Boundary markers: The instructions do not explicitly mandate the use of delimiters (e.g., XML tags or triple quotes) when the agent processes the external code.
- Capability inventory: The skill includes file-writing capabilities in Step 4 of SKILL.md to apply security remediations.
- Sanitization: No explicit sanitization or validation of the ingested code/data is defined.
- Contextual Note: As the primary purpose of this skill is cybersecurity risk assessment, the processing of untrusted code is an intended functionality. The skill includes strong guardrails against following instructions within analyzed data (Step 4 explicitly limits changes).
Audit Metadata