review-implementation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze external "implementation evidence," "data flows," and "user workflows." This ingestion of untrusted external content represents an attack surface where malicious instructions could be hidden within reviewed code or documents to influence the agent's behavior.
  • Ingestion points: User-provided implementation details, data flow artifacts, and interface documentation (SKILL.md).
  • Boundary markers: Absent; the instructions do not require the agent to use specific delimiters or to treat reviewed code as untrusted data.
  • Capability inventory: The skill directs the agent to "fix root causes," "implement the simplest coherent end state," and "improve or fix" implementations (SKILL.md), which involves write access to project files.
  • Sanitization: Absent; there is no mention of validating, filtering, or escaping content extracted from external sources.
  • [NO_CODE]: The skill consists entirely of natural language guidelines and configuration files; it does not distribute scripts, binaries, or external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:00 PM
Security Audit — agent-trust-hub — review-implementation