skills/jybill/xqv-skills/summary/Gen Agent Trust Hub

summary

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted source code files (including comments and TODOs) which presents a standard surface for indirect prompt injection. While malicious instructions could be embedded in code comments, this is an inherent risk of code analysis tools and is handled safely here through specific documentation-focused instructions.
  • Ingestion points: Reads user-specified source code files and their dependencies (imports, services, etc.) from the local repository.
  • Boundary markers: The skill uses structured writing requirements and specific section headers to guide the output, though it does not explicitly define markers for untrusted code segments.
  • Capability inventory: The skill is capable of reading repository files, writing documentation files to the docs/spec/ directory, and checking git status/diff.
  • Sanitization: Not explicitly mentioned, as the primary task is summarization rather than execution of the code content.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 05:56 AM
Security Audit — agent-trust-hub — summary