brooks-review

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied code snippets and PR diffs, which are external data sources that could potentially contain malicious instructions hidden in comments.
  • Ingestion points: Analyzes code, files, and diffs provided by the user for review (SKILL.md, pr-review-guide.md).
  • Boundary markers: Absent; the instructions do not include specific delimiters or directives to ignore natural language instructions found within the code being analyzed.
  • Capability inventory: None; the skill does not use tools for network communication, filesystem writing, or shell command execution, effectively nullifying the risk of injection.
  • Sanitization: None identified in the provided process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:45 PM
Security Audit — agent-trust-hub — brooks-review