drupal-theme-review

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and reviews external source code provided via file paths or direct input.
  • Ingestion points: Processes file and directory content from $ARGUMENTS and user-supplied code snippets in SKILL.md.
  • Boundary markers: The instructions enforce a structured auditing process and provide detailed reference files (references/) to focus the agent's behavior.
  • Capability inventory: The skill utilizes Read, Glob, and Grep to access and analyze the target codebase.
  • Sanitization: The skill's primary purpose is to validate user code, specifically instructing the agent to flag dangerous Twig filters like |raw and other insecure patterns.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references external resources from well-known services and official repositories.
  • Evidence: Includes references to the Swiper library on unpkg.com (a well-known CDN) in references/03-libraries.md and the official Drupal metadata schema on drupalcode.org (the official project repository) in references/05-sdc.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 07:10 PM
Security Audit — agent-trust-hub — drupal-theme-review