excellence-review

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from untrusted external sources, including web content via the 'gstack' headless browser and code from local repositories via 'repo-mastery'.
  • Ingestion points: External websites accessed via 'gstack' and cross-repo files mapped via 'repo-mastery' (SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters or specify that the agent should ignore instructions embedded within the processed content.
  • Capability inventory: The skill has access to a terminal for executing tests and can delegate tasks to subagents (SKILL.md).
  • Sanitization: There is no evidence of content sanitization or validation before the ingested data influences the agent's behavior or terminal commands.
  • [COMMAND_EXECUTION]: The skill explicitly utilizes a terminal for running tests and artifacts generation. While standard for review tasks, this capability allows for code execution that could be targeted by malicious payloads if the input data is compromised.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 11:06 AM
Security Audit — agent-trust-hub — excellence-review