skills/poteto/plugins/deslop/Gen Agent Trust Hub

deslop

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external code diffs, serving as an ingestion point for untrusted data that could contain indirect prompt injections.
  • Ingestion points: Reads code diffs against the main branch to identify AI-generated patterns.
  • Boundary markers: Lacks explicit markers to distinguish code content from instructions.
  • Capability inventory: Implies file-writing permissions to perform code cleanup.
  • Sanitization: No validation or escaping of the processed code is mentioned.
  • [NO_CODE]: The skill is purely instructional and does not package any executable code or scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 03:44 PM
Security Audit — agent-trust-hub — deslop