technical-quality-perspective

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input such as code diffs, architecture documents, and requirements. It includes instructions to distinguish facts from inference and follow a strict output format, which helps mitigate potential injection risks from the processed data. This represents a standard attack surface for analysis-oriented skills.
  • Ingestion points: Project materials (code, diffs, requirements, contracts) provided via the prompt during runtime.
  • Boundary markers: The skill requires findings to be evidence-backed and instructs the agent to use a specific report contract (Summary, Facts, Evidence, etc.).
  • Capability inventory: None. The skill only generates text-based reports and does not invoke shell commands, network requests, or file writes.
  • Sanitization: The instructions emphasize labeling inference and gaps, avoiding invented implementation facts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 02:59 PM
Security Audit — agent-trust-hub — technical-quality-perspective