fullstack-reviewer

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as its primary function involves processing untrusted code from a repository workspace.\n
  • Ingestion points: The skill reads source code from the project workspace across frontend, backend, and contract subsystems (SKILL.md).\n
  • Boundary markers: The instructions do not define delimiters or provide warnings to ignore or isolate instructions found within the code being reviewed.\n
  • Capability inventory: The skill utilizes 'shell' and 'workspace' MCP servers, enabling it to read files and potentially perform shell commands such as git operations (SKILL.md, templates/release_summary.md).\n
  • Sanitization: There is no evidence of sanitization, escaping, or validation of the ingested code content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:55 AM
Security Audit — agent-trust-hub — fullstack-reviewer