angular-expert

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and review code from the user's workspace, which constitutes untrusted data. Because the skill is equipped with powerful tools like Bash, Write, and Edit, it possesses a theoretical attack surface where malicious instructions embedded in reviewed code could attempt to influence the agent's behavior.
  • Ingestion points: The agent is instructed to read code files for review and to access .claude/context/memory/learnings.md as part of its memory protocol.
  • Boundary markers: There are no explicit instructions or delimiters defined to help the agent distinguish between code content and potential malicious instructions embedded within that code.
  • Capability inventory: The skill allows the use of Read, Write, Edit, Bash, Grep, and Glob tools.
  • Sanitization: The skill lacks specific instructions for sanitizing, filtering, or validating the content of the files it ingests before processing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:58 AM
Security Audit — agent-trust-hub — angular-expert