skill-reviewer
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by reading other skill definition files within the
.claude/skills/directory as specified by$ARGUMENTS. - Ingestion points: reads
SKILL.mdand referenced files in the target directory. - Boundary markers: None present; the skill treats all file content as data to be audited.
- Capability inventory: Limited to
Read,Glob, andGreptools. No file-write, network, or code execution capabilities are requested. - Sanitization: None detected.
- Assessment: While the skill has an attack surface for indirect prompt injection, its lack of dangerous capabilities (no network, no shell execution) makes this risk negligible in its primary use case as a local auditor.
Audit Metadata