skill-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by reading other skill definition files within the .claude/skills/ directory as specified by $ARGUMENTS.
  • Ingestion points: reads SKILL.md and referenced files in the target directory.
  • Boundary markers: None present; the skill treats all file content as data to be audited.
  • Capability inventory: Limited to Read, Glob, and Grep tools. No file-write, network, or code execution capabilities are requested.
  • Sanitization: None detected.
  • Assessment: While the skill has an attack surface for indirect prompt injection, its lack of dangerous capabilities (no network, no shell execution) makes this risk negligible in its primary use case as a local auditor.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:53 PM
Security Audit — agent-trust-hub — skill-reviewer