challenge
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface by instructing the agent to ingest and analyze external data from the codebase and local review logs (stored in
.claude/reviews/). While this is an inherent aspect of a code review tool, the skill lacks explicit boundary markers to differentiate between code data and instructions. - [SAFE]: The skill implements logic to search and read local project directories for state management and deduplication. These operations are scoped to the local environment and do not involve unauthorized data exfiltration, network requests, or remote code execution.
Audit Metadata