sqlalchemy-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional markdown and educational code snippets providing best practices for SQLAlchemy code reviews.
- [SAFE]: No evidence of prompt injection, role-play bypasses, or instructions to ignore safety filters was found in the review protocols.
- [SAFE]: The skill does not perform any network operations, external downloads, or sensitive file access. All code snippets are illustrative placeholders for educational purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing untrusted data (source code under review).
- Ingestion points: The agent is instructed to open and read project modules and Alembic revision files (SKILL.md, Gate 1a, Gate 3a).
- Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are suggested for the reviewed code.
- Capability inventory: The skill instructions and reference files do not contain any network requests, file-writing operations, or shell command execution capabilities.
- Sanitization: No sanitization is performed, but the lack of exploitable capabilities makes the risk negligible.
- [OBFUSCATION]: The content was scanned for Base64 encoding, zero-width characters, homoglyphs, and hidden text patterns; no obfuscation was detected.
- [DYNAMIC_CONTEXT_INJECTION]: The skill does not use the dynamic exclamation mark syntax to execute shell commands at load time.
Audit Metadata