review
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided code and diffs, which are external and untrusted data sources. This represents a potential surface for indirect prompt injection attacks where malicious instructions could be embedded in the code being reviewed.
- Ingestion points: User-provided source code and diffs in SKILL.md.
- Boundary markers: No specific delimiters or instructions to ignore embedded commands are defined.
- Capability inventory: The skill does not define any tool usage, file system operations, or network requests.
- Sanitization: No sanitization or input validation of the code being reviewed is performed.
- [NO_CODE]: The skill consists entirely of natural language instructions and does not include any scripts, binaries, or configuration files that could execute code on the host system.
- [SAFE]: The skill promotes positive security outcomes by instructing the agent to look for common vulnerabilities like SQL injection, XSS, and race conditions. No credential harvesting, data exfiltration, or persistence mechanisms are present.
Audit Metadata