simplify
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses both an ingestion point for untrusted data and the capability to modify the filesystem, creating a surface for indirect prompt injection.
- Ingestion points: In Phase 1 of SKILL.md, the skill identifies changes using 'git diff' or by reading recently modified files.
- Boundary markers: The instructions lack explicit boundary markers or instructions telling the sub-agents to disregard potential instructions embedded within the code or comments being reviewed.
- Capability inventory: The skill is tasked with fixing issues directly in Phase 3, which involves writing changes to the codebase.
- Sanitization: There is no evidence of sanitization or validation of the code content before it is processed and acted upon by the analysis agents.
Audit Metadata