bubbletea-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied Go source code for review, which creates an indirect prompt injection surface. * Ingestion points: User code is provided as input for analysis according to the instructions in SKILL.md. * Boundary markers: The skill defines a specific 'review-verification-protocol' (Gate G3) to ensure findings are validated before being finalized. * Capability inventory: The skill does not request tool access or execute system-level commands; it is limited to static analysis and text generation. * Sanitization: No specific sanitization of ingested code is mentioned, relying on agent-level safety filters and the defined sequential gates.
  • [SAFE]: The skill documentation and reference files contain only legitimate technical guidance for the Bubble Tea framework and exhibit no signs of malicious intent or unauthorized data access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:52 PM
Security Audit — agent-trust-hub — bubbletea-code-review