code-review-dangerous-sinks

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted source code (PHP, Python, JavaScript, Java, Ruby, Go, .NET/C#) which provides an attack surface for instructions embedded in data to influence the agent.
  • Ingestion points: Source code files processed during code review as described in the skill.
  • Boundary markers: No specific delimiters are defined to separate code content from instructions.
  • Capability inventory: The skill leverages external tools like ripgrep and semgrep to search through files.
  • Sanitization: The instructions do not specify any validation or sanitization of the source code content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:01 PM
Security Audit — agent-trust-hub — code-review-dangerous-sinks