bubbletea-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied Go source code for review, which creates an indirect prompt injection surface. * Ingestion points: User code is provided as input for analysis according to the instructions in SKILL.md. * Boundary markers: The skill defines a specific 'review-verification-protocol' (Gate G3) to ensure findings are validated before being finalized. * Capability inventory: The skill does not request tool access or execute system-level commands; it is limited to static analysis and text generation. * Sanitization: No specific sanitization of ingested code is mentioned, relying on agent-level safety filters and the defined sequential gates.
- [SAFE]: The skill documentation and reference files contain only legitimate technical guidance for the Bubble Tea framework and exhibit no signs of malicious intent or unauthorized data access.
Audit Metadata