drupal-review
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill consists entirely of Markdown reference files and instructions for performing static code analysis on Drupal projects.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted code (provided via file paths in
$ARGUMENTSor user input), creating a surface for indirect prompt injection. - Ingestion points: The
SKILL.mdfile instructs the agent to read files specified in$ARGUMENTSor process inline code. - Boundary markers: Absent. The skill does not explicitly define delimiters to isolate the code under review from its own instructions.
- Capability inventory: The skill uses
Read,Grep, andGlobtools. It lacks network access or file-writing capabilities, significantly limiting the impact of any potential injection. - Sanitization: None. The skill assumes the agent can safely interpret the provided code snippets as data to be reviewed.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. While the documentation in
references/11-theming.mdandreferences/13-deployment.mdmentions external URLs for libraries (e.g., Swiper via Unpkg) and schema definitions (official Drupal Git), these are documented as standard practices for developers and are not executed by the skill itself.
Audit Metadata