skills/gannonh/skills/thermo-run/Gen Agent Trust Hub

thermo-run

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it processes untrusted external data.
  • Ingestion points: Processes user requests, PR metadata, and branch diffs to determine review scope (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded commands within the processed files.
  • Capability inventory: Orchestrates two sub-skills (/skill:thermo-nuclear-review and /skill:thermo-nuclear-code-quality-review) and synthesizes their output into a final verdict.
  • Sanitization: No sanitization or filtering of external content is performed before interpolation into the review context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:21 PM
Security Audit — agent-trust-hub — thermo-run