drupal-review

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill consists entirely of Markdown reference files and instructions for performing static code analysis on Drupal projects.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted code (provided via file paths in $ARGUMENTS or user input), creating a surface for indirect prompt injection.
  • Ingestion points: The SKILL.md file instructs the agent to read files specified in $ARGUMENTS or process inline code.
  • Boundary markers: Absent. The skill does not explicitly define delimiters to isolate the code under review from its own instructions.
  • Capability inventory: The skill uses Read, Grep, and Glob tools. It lacks network access or file-writing capabilities, significantly limiting the impact of any potential injection.
  • Sanitization: None. The skill assumes the agent can safely interpret the provided code snippets as data to be reviewed.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. While the documentation in references/11-theming.md and references/13-deployment.md mentions external URLs for libraries (e.g., Swiper via Unpkg) and schema definitions (official Drupal Git), these are documented as standard practices for developers and are not executed by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 07:10 PM
Security Audit — agent-trust-hub — drupal-review