review
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill reviews untrusted documentation and source code from the workspace, which presents a surface for indirect prompt injection.
- Ingestion points: Project source files, README, PRD, and jtbd.json files.
- Boundary markers: The orchestration layer does not define specific delimiters for separating processed data from instructions.
- Capability inventory: The agent can read local files, launch sub-agents, and perform browser-based walkthroughs.
- Sanitization: Data is ingested for review purposes without additional sanitization logic.
- [COMMAND_EXECUTION]: The skill can execute local project checks and the 'tokens contrast' utility to verify audit results, which is expected behavior for its design auditing purpose.
Audit Metadata