drupal-theme-review
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and reviews external source code provided via file paths or direct input.
- Ingestion points: Processes file and directory content from
$ARGUMENTSand user-supplied code snippets inSKILL.md. - Boundary markers: The instructions enforce a structured auditing process and provide detailed reference files (
references/) to focus the agent's behavior. - Capability inventory: The skill utilizes
Read,Glob, andGrepto access and analyze the target codebase. - Sanitization: The skill's primary purpose is to validate user code, specifically instructing the agent to flag dangerous Twig filters like
|rawand other insecure patterns. - [EXTERNAL_DOWNLOADS]: The skill documentation references external resources from well-known services and official repositories.
- Evidence: Includes references to the Swiper library on
unpkg.com(a well-known CDN) inreferences/03-libraries.mdand the official Drupal metadata schema ondrupalcode.org(the official project repository) inreferences/05-sdc.md.
Audit Metadata