security-review
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of high-quality educational and procedural instructions for performing security audits.
- [COMMAND_EXECUTION]: The skill instructs the agent to use common, trusted developer tools such as git grep and established static analysis scanners (e.g., Semgrep, CodeQL) if they are already present in the user's environment.
- [PROMPT_INJECTION]: The skill describes a workflow for analyzing external, untrusted content (code diffs and source files), which is a known surface for indirect prompt injection. This behavior is necessary for the skill's primary function of code review and is handled through the agent's reasoning process rather than automated execution of the untrusted data.
Audit Metadata