fullstack-reviewer
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as its primary function involves processing untrusted code from a repository workspace.\n
- Ingestion points: The skill reads source code from the project workspace across frontend, backend, and contract subsystems (SKILL.md).\n
- Boundary markers: The instructions do not define delimiters or provide warnings to ignore or isolate instructions found within the code being reviewed.\n
- Capability inventory: The skill utilizes 'shell' and 'workspace' MCP servers, enabling it to read files and potentially perform shell commands such as git operations (SKILL.md, templates/release_summary.md).\n
- Sanitization: There is no evidence of sanitization, escaping, or validation of the ingested code content before it is processed by the agent.
Audit Metadata