skills/poteto/noodle/review/Gen Agent Trust Hub

review

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as code, diffs, and plans which may contain malicious instructions designed to influence the agent's behavior during the review process.
  • Ingestion points: The agent reads project principles from brain/principles.md, user-provided messages, code diffs, referenced plans, and the output from other domain-specific skills found via find-skills.
  • Boundary markers: The instructions lack specific delimiters or warnings for the agent to ignore instructions embedded within the code or documentation being reviewed.
  • Capability inventory: The skill uses Task management tools (TaskCreate, TaskUpdate), find-skills, spawns Explore subagents, writes report files to brain/audits/, interacts with brain/todos.md via the /todo skill, and concludes by committing files.
  • Sanitization: No evidence of sanitization or filtering is present for the data ingested from the project files or user context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:00 AM