deslop
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes external code diffs, serving as an ingestion point for untrusted data that could contain indirect prompt injections.
- Ingestion points: Reads code diffs against the main branch to identify AI-generated patterns.
- Boundary markers: Lacks explicit markers to distinguish code content from instructions.
- Capability inventory: Implies file-writing permissions to perform code cleanup.
- Sanitization: No validation or escaping of the processed code is mentioned.
- [NO_CODE]: The skill is purely instructional and does not package any executable code or scripts.
Audit Metadata