skills/linnanli/xclaw/code-simplifier/Gen Agent Trust Hub

code-simplifier

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes externally provided or recently modified code snippets, creating a surface for potential indirect prompt injection attacks. \n- Ingestion points: The agent is instructed to analyze and optimize recently modified code within the session (specified in SKILL.md workflow). \n- Boundary markers: The instructions do not specify the use of delimiters (such as XML tags or markdown code blocks) or explicit 'ignore embedded instructions' warnings for the code being processed. \n- Capability inventory: The skill is limited to providing code recommendations and text output; it does not request access to shell execution, network operations, or file-writing tools. \n- Sanitization: No input validation or content filtering of the code snippets is implemented to detect or strip instructions hidden in comments or strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:21 PM
Security Audit — agent-trust-hub — code-simplifier