code-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze source code, creating a surface for instructions embedded in that code to influence the agent's actions.
- Ingestion points: Source code is read into the context using the
Readtool as specified in the Instructions. - Boundary markers: No specific delimiters or instructions to ignore content within the files are present in the skill definition to differentiate between instructions and data.
- Capability inventory: Capabilities are limited to read-only filesystem access via the
Read,Grep, andGlobtools; no network access or file-write permissions are granted in the frontmatter configuration. - Sanitization: There is no evidence of sanitization or filtering applied to the ingested content before it is processed by the agent.
Audit Metadata