engram-pr-review-deep
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for processing untrusted data that could contain malicious instructions.
- Ingestion points: The agent is instructed to read the full diff of external or internal pull request contributions (SKILL.md).
- Boundary markers: There are no instructions to use delimiters or to ignore embedded instructions within the pull request content.
- Capability inventory: The review protocol directs the agent to run tests locally, which creates an execution surface for code provided by the contributor.
- Sanitization: The skill does not specify any sanitization, validation, or sandboxing requirements for the code before execution.
Audit Metadata