review
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze external software designs and code implementations, which serves as a potential vector for indirect prompt injection if the source material contains hidden malicious instructions.
- Ingestion points: The 'Evaluate' section in SKILL.md requires the agent to trace callers, interfaces, and designs provided as input.
- Boundary markers: There are no explicit instructions to use delimiters or to disregard embedded commands within the content being reviewed.
- Capability inventory: The skill focus is restricted to inspection and reporting; it does not invoke shell commands, file writes, or network operations.
- Sanitization: The skill does not provide mechanisms to sanitize or filter the content before processing.
Audit Metadata