adversarial-zod
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides a structured framework for code review focused on Zod 4 migration rules and TypeScript best practices. No malicious code, unauthorized command execution, or obfuscation was found in the provided files.\n- [PROMPT_INJECTION]: The skill ingests untrusted data in the form of code diffs and project files as part of its review target. This creates an attack surface for indirect prompt injection. However, the risk is mitigated by the reviewer subagent's lack of tool access and the use of a self-contained prompt without conversation history, ensuring any potential injection cannot escalate into unauthorized actions or data exfiltration. The skill follows the security best practice of context isolation for its evaluation task.
Audit Metadata