check-query-safety
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process and analyze external source code, creating a surface for indirect prompt injection attacks where malicious instructions could be embedded in the code being reviewed.
- Ingestion points: The skill ingests untrusted data in the form of code snippets or file contents provided in the user's request (e.g., SKILL.md instructions to 'Review database queries in a file or module').
- Boundary markers: There are no instructions for the agent to use specific delimiters or to disregard natural language instructions found within the input code context.
- Capability inventory: The skill is restricted to text analysis and does not utilize dangerous tools like shell execution, network access, or file writes.
- Sanitization: The instructions do not define any validation or sanitization steps for the input code before it is processed by the model.
- [NO_CODE]: The skill does not include any executable scripts or binary files, consisting solely of markdown instructions and evaluation criteria. This significantly limits the potential for direct system compromise or remote code execution by the skill itself.
Audit Metadata