cleanup
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting and processing branch code changes.
- Ingestion points: The skill retrieves uncommitted and outgoing changes from the user's current branch.
- Boundary markers: The instructions do not define explicit delimiters or 'ignore' commands to separate the code being analyzed from the agent's control logic.
- Capability inventory: The skill can analyze source files, generate refactoring suggestions, and invoke the /prose-review tool.
- Sanitization: There is no mention of sanitization, filtering, or validation of the ingested code to prevent instruction leakage from comments or strings.
Audit Metadata