review-auth
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill is composed entirely of markdown instructions and evaluation criteria. It does not include any executable scripts, binaries, or configuration files that would run code on the host system.
- [SAFE]: The instructions are designed for defensive security purposes and follow standard auditing practices. No attempts at credential harvesting, persistence, or data exfiltration were identified.
- [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest and audit untrusted source code provided by users, it inherently possesses an indirect prompt injection attack surface. A malicious code snippet could contain instructions intended to bypass the agent's security logic or misrepresent its security posture.
- Ingestion points: Untrusted source code provided by the user within the chat prompt for analysis (as defined in SKILL.md).
- Boundary markers: Absent; the instructions do not specify the use of delimiters or specific system instructions to ignore content within the code blocks being audited.
- Capability inventory: The skill is limited to generating text reports and does not have access to file writing, network operations, or shell command execution.
- Sanitization: None; the skill processes raw code text provided by the user.
Audit Metadata