angular-expert
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and review code from the user's workspace, which constitutes untrusted data. Because the skill is equipped with powerful tools like
Bash,Write, andEdit, it possesses a theoretical attack surface where malicious instructions embedded in reviewed code could attempt to influence the agent's behavior. - Ingestion points: The agent is instructed to read code files for review and to access
.claude/context/memory/learnings.mdas part of its memory protocol. - Boundary markers: There are no explicit instructions or delimiters defined to help the agent distinguish between code content and potential malicious instructions embedded within that code.
- Capability inventory: The skill allows the use of
Read,Write,Edit,Bash,Grep, andGlobtools. - Sanitization: The skill lacks specific instructions for sanitizing, filtering, or validating the content of the files it ingests before processing them.
Audit Metadata