developer-qa-reviewer

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted "Generated Source Code Files" and "Sprint Tickets", creating a surface for indirect prompt injection.
  • Ingestion points: Audits external source code and acceptance criteria.
  • Boundary markers: Absent; no delimiters are used to separate user data from instructions.
  • Capability inventory: High-power capabilities including browser automation (computer-use, chrome-devtools-mcp) and CLI tool execution (graphify).
  • Sanitization: Absent; no content validation is performed.
  • [COMMAND_EXECUTION]: The skill is instructed to run command-line tools for auditing.
  • Evidence: Executes graphify query and graphify path.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources for automation fallbacks.
  • Evidence: Mentions stablyai/orca@computer-use, midscene-skills@computer-automation, and codex-skills@gemini-computer-use as external skills for automation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 02:03 PM
Security Audit — agent-trust-hub — developer-qa-reviewer