brooks-debt

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied codebase content to identify technical debt, creating a surface for indirect prompt injection if the source code contains instructions designed to subvert the agent's analysis.
  • Ingestion points: The skill ingests and scans external codebases or code snippets provided by the user as specified in SKILL.md and debt-guide.md.
  • Boundary markers: Uses specific analytical frameworks like the 'Iron Law' (Symptom, Source, Consequence, Remedy) and a 'Debt Summary Table' to structure findings.
  • Capability inventory: No risky capabilities such as network access, arbitrary command execution, or file system writes are defined within the skill itself.
  • Sanitization: No explicit sanitization of codebase content is mentioned in the analysis process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:28 PM
Security Audit — agent-trust-hub — brooks-debt