queue-workers
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill serves as a code auditing tool, which involves ingesting and processing untrusted user-provided source code. This creates a potential surface for instructions embedded within the user's code to influence the agent.
- Ingestion points: Source code files (
**/*.ts,**/*.js) provided by the user for review and diagnosis as specified inSKILL.mdandreferences/validations.md. - Boundary markers: The instructions do not define specific delimiters or "ignore" directives to isolate the user-provided code from the agent's internal reasoning.
- Capability inventory: The skill itself contains no definitions for network requests, file system writes, or shell command execution, which significantly mitigates the risk of this ingestion surface being exploited.
- Sanitization: The skill does not specify any sanitization or filtering protocols for the ingested source code.
- [SAFE]: The skill demonstrates safe behavior by utilizing environment variables for Redis connection strings and providing robust error handling and recovery patterns. No evidence of obfuscation, persistence mechanisms, or unauthorized privilege escalation was found in the provided instructions or reference files.
Audit Metadata