skills/lvlup-sw/exarchos/review/Gen Agent Trust Hub

review

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code diffs and design specifications without implementing specific boundary markers, creating a surface for indirect prompt injection attacks where instructions embedded in code comments could manipulate the reviewer's verdict.
  • Ingestion points: Integrated branch diffs and state-file artifacts are passed to the subagent (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to disregard commands within the analyzed data.
  • Capability inventory: The skill can update workflow state, transition between phases (exarchos_workflow), and auto-invoke follow-up skills such as 'synthesize', 'delegate', and 'ideate' (references/auto-transition.md).
  • Sanitization: Although the skill runs an automated security scan (references/gate-execution.md), it lacks internal prompt-level sanitization or instructions for the subagent to ignore commands found within the diff content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 12:27 AM
Security Audit — agent-trust-hub — review