37signals-review

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and documentation focus on improving code quality and security without introducing malicious logic.- [SAFE]: No credential exposure, sensitive file access, or unauthorized network communication was detected.- [SAFE]: No remote code execution, persistence mechanisms, or privilege escalation patterns were found.- [SAFE]: Indirect Prompt Injection: The skill reviews user-provided code (Ingestion Point: diff input). Boundary markers are absent. Capability inventory includes no subprocess or network operations. Sanitization is absent. The risk is evaluated as safe given the lack of exploitable tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 05:01 PM
Security Audit — agent-trust-hub — 37signals-review