engram-pr-review-deep

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for processing untrusted data that could contain malicious instructions.
  • Ingestion points: The agent is instructed to read the full diff of external or internal pull request contributions (SKILL.md).
  • Boundary markers: There are no instructions to use delimiters or to ignore embedded instructions within the pull request content.
  • Capability inventory: The review protocol directs the agent to run tests locally, which creates an execution surface for code provided by the contributor.
  • Sanitization: The skill does not specify any sanitization, validation, or sandboxing requirements for the code before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:01 PM
Security Audit — agent-trust-hub — engram-pr-review-deep