review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as code, diffs, and plans which may contain malicious instructions designed to influence the agent's behavior during the review process.
- Ingestion points: The agent reads project principles from
brain/principles.md, user-provided messages, code diffs, referenced plans, and the output from other domain-specific skills found viafind-skills. - Boundary markers: The instructions lack specific delimiters or warnings for the agent to ignore instructions embedded within the code or documentation being reviewed.
- Capability inventory: The skill uses
Taskmanagement tools (TaskCreate,TaskUpdate),find-skills, spawnsExploresubagents, writes report files tobrain/audits/, interacts withbrain/todos.mdvia the/todoskill, and concludes by committing files. - Sanitization: No evidence of sanitization or filtering is present for the data ingested from the project files or user context.
Audit Metadata