code-tour
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase data to generate narrative walkthroughs, which could theoretically contain embedded instructions that influence the agent's output descriptions.
- Ingestion points: The skill reads repository source files, READMEs, and configuration files during discovery and anchor verification steps in
SKILL.md. - Boundary markers: No specific delimiters or "ignore instructions" wrappers are defined for the code content being analyzed.
- Capability inventory: The skill is authorized to write
.tourJSON files to the.tours/directory. - Sanitization: There are no explicit instructions for sanitizing or escaping content extracted from the source code before it is used in the tour's
descriptionfields. - Note: This is a low-severity architectural risk common to all code-analysis skills and is mitigated by the highly structured JSON output schema.
- [EXTERNAL_DOWNLOADS]: The skill references the
microsoft/codetourupstream format and schema. - Evidence: Mentions
microsoft/codetouras a related skill and useshttps://aka.ms/codetour-schemafor the JSON validation schema. - Note: These are references to a well-known service and official schema definition, presenting no security risk.
Audit Metadata