code-tour

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase data to generate narrative walkthroughs, which could theoretically contain embedded instructions that influence the agent's output descriptions.
  • Ingestion points: The skill reads repository source files, READMEs, and configuration files during discovery and anchor verification steps in SKILL.md.
  • Boundary markers: No specific delimiters or "ignore instructions" wrappers are defined for the code content being analyzed.
  • Capability inventory: The skill is authorized to write .tour JSON files to the .tours/ directory.
  • Sanitization: There are no explicit instructions for sanitizing or escaping content extracted from the source code before it is used in the tour's description fields.
  • Note: This is a low-severity architectural risk common to all code-analysis skills and is mitigated by the highly structured JSON output schema.
  • [EXTERNAL_DOWNLOADS]: The skill references the microsoft/codetour upstream format and schema.
  • Evidence: Mentions microsoft/codetour as a related skill and uses https://aka.ms/codetour-schema for the JSON validation schema.
  • Note: These are references to a well-known service and official schema definition, presenting no security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — code-tour