nestjs-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted source code, which serves as a potential vector for indirect prompt injection.
- Ingestion points: The agent reads local NestJS source files (controllers, services, modules) via the
Read,Glob, andGreptools. - Boundary markers: There are no instructions requiring the use of delimiters or specific directives to ignore prompts embedded in the source code or comments.
- Capability inventory: The agent possesses
Bash,Edit, andReadpermissions, which could be leveraged if an embedded prompt is followed. - Sanitization: No procedures for sanitizing or filtering input from analyzed files are specified.
Audit Metadata