fresh-eyes-grill
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted content such as staged diffs and source files, which creates a potential surface for indirect prompt injection.\n
- Ingestion points: The skill reads user-specified files and staged diffs as part of its core logic in
SKILL.md.\n - Boundary markers: Instructions include the use of a "bounded prompt" for subagents, which serves as a mitigation technique to limit context.\n
- Capability inventory: The skill's workflow involves reading local files and spawning subagents for specialized analysis.\n
- Sanitization: The skill does not explicitly detail sanitization or escaping procedures for the content of the code being reviewed before it is presented to the model.
Audit Metadata