security-reviewer

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a guide for identifying common security vulnerabilities such as SQL injection, XSS, and hardcoded secrets. It follows security best practices, such as recommending the use of parameterized queries and the rotation of compromised secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted code provided by the user, which presents an inherent surface for indirect prompt injection. However, this behavior is central to its stated purpose as a security auditor.
  • Ingestion points: External files or directories provided for review as part of the 'Process' section.
  • Boundary markers: None specified for separating reviewed code from instructions.
  • Capability inventory: Use of grep for scanning and file reading operations to confirm vulnerabilities.
  • Sanitization: The skill does not specify sanitization for the analyzed code, focusing instead on reporting detected vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 04:39 PM
Security Audit — agent-trust-hub — security-reviewer