can-this-throw
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external and potentially untrusted code artifacts provided by the user.
- Ingestion points: The skill ingests user-provided code from Pull Requests, diff ranges, or file snippets as its primary input for analysis (SKILL.md).
- Boundary markers: There are no instructions or delimiters defined to separate the code being analyzed from the agent's operational instructions, which could allow instructions embedded in code comments or strings to influence the agent's verdict.
- Capability inventory: The skill leverages the agent's code reasoning capabilities to perform static analysis. While no dangerous tools (like shell execution) are explicitly invoked in the instructions, the analysis is intended to inform human review and approval processes.
- Sanitization: The instructions do not define any sanitization, filtering, or escaping protocols for the code inputs before they are processed by the agent.
Audit Metadata