cmd-review-rfc
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists exclusively of natural language instructions for a document review task. No executable code, shell commands, hardcoded secrets, or network-enabled operations were found.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection attack surface as it is designed to process untrusted RFC documents. 1. Ingestion points: RFC text provided for review. 2. Boundary markers: Absent; the prompt does not specify delimiters for the analyzed content. 3. Capability inventory: The skill is restricted to generating text responses and does not use tools or subprocesses. 4. Sanitization: Absent; there are no instructions to ignore malicious content within the reviewed text. This surface is considered low risk because the agent lacks sensitive capabilities to exploit.
Audit Metadata