python-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted Python source code, which creates a surface for indirect prompt injection. 1. Ingestion points: Source code files (.py) identified by the agent as per instructions in SKILL.md. 2. Boundary markers: None specified; the agent is not instructed to use specific delimiters when reading external code. 3. Capability inventory: The skill is restricted to providing textual analysis and contains no instructions for subprocess execution, file modification, or network requests. 4. Sanitization: There are no requirements for sanitizing or escaping the content of the reviewed code before processing.
- [NO_CODE]: The skill consists entirely of Markdown guidelines and reference files; no executable scripts (Python, JavaScript, shell) are included.
Audit Metadata