thermo-nuclear-review

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch and take into account findings from PR/MR discussions using the gh or glab CLI tools.
  • Ingestion points: Pull request and Merge request discussion comments (SKILL.md).
  • Boundary markers: Absent. The instructions do not specify delimiters or warnings to ignore potentially malicious instructions embedded within those external comments.
  • Capability inventory: The agent is authorized to use version control CLI tools (gh, glab) and has read access to the local codebase.
  • Sanitization: Absent. There are no requirements for the agent to sanitize, escape, or validate the content retrieved from the discussion threads before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:02 AM
Security Audit — agent-trust-hub — thermo-nuclear-review