detect-magic
Pass
Audited by Gen Agent Trust Hub on Jun 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or suspicious code were detected. The skill is purely instructional and guides the agent through a logical repository analysis process.
- [INDIRECT_PROMPT_INJECTION]: The skill functions by scanning untrusted project files, creating an attack surface for indirect prompt injection.
- Ingestion points: Files within a repository or system being scanned (SKILL.md).
- Boundary markers: The procedure requires the agent to restate "no-touch boundaries" before beginning the scan, providing a safety checkpoint.
- Capability inventory: The skill utilizes the agent's native environment tools (such as file reading and searching) rather than providing custom executables.
- Sanitization: No specific content filtering or sanitization is mentioned, though the instructions explicitly warn against executing discovered hooks or automations.
Audit Metadata