zero-tech-debt
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions involve processing and modifying external source code, which creates a potential surface for instructions embedded within that code to influence agent behavior.
- Ingestion points: Source code and patches provided by the user to the agent, as guided by instructions in SKILL.md.
- Boundary markers: None; there are no explicit instructions to the agent to treat input code strictly as data or to ignore embedded comments/instructions.
- Capability inventory: The skill directs the agent to search for code callers and delete compatibility paths, involving read and write/edit operations.
- Sanitization: None; the skill does not specify any validation or filtering of the code being refactored.
Audit Metadata