analytics
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided content (such as source code and data metrics) for diagnosis and review tasks. It lacks explicit instructions for the agent to use boundary markers or to treat ingested data as untrusted, which is a standard surface for indirect prompt injection.
- Ingestion points: User-provided files (*.js, *.jsx, *.ts, *.tsx, *.py) and product metrics shared for analysis in the SKILL.md tasks.
- Boundary markers: Absent; the skill does not instruct the agent to use specific delimiters or to ignore instructions for external content.
- Capability inventory: The skill performs diagnosis and validation (reviewing code patterns against rules in
references/validations.mdand logic inreferences/sharp_edges.md). - Sanitization: Absent; the skill does not specify filtering or escaping mechanisms for the data it processes.
Audit Metadata