cmd-review-rfc

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists exclusively of natural language instructions for a document review task. No executable code, shell commands, hardcoded secrets, or network-enabled operations were found.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection attack surface as it is designed to process untrusted RFC documents. 1. Ingestion points: RFC text provided for review. 2. Boundary markers: Absent; the prompt does not specify delimiters for the analyzed content. 3. Capability inventory: The skill is restricted to generating text responses and does not use tools or subprocesses. 4. Sanitization: Absent; there are no instructions to ignore malicious content within the reviewed text. This surface is considered low risk because the agent lacks sensitive capabilities to exploit.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:16 AM
Security Audit — agent-trust-hub — cmd-review-rfc