review-security-report

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions for human-in-the-loop security triage. It does not include scripts, binaries, or automated tool configurations.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data (security reports, proof-of-concept code, and bug bounty submissions). This inherent attack surface is noted, although the skill focuses on providing analytical guidelines rather than automated processing logic.
  • Ingestion points: External vulnerability reports, comments, and proof-of-concept files (SKILL.md).
  • Boundary markers: Absent; the skill does not define specific delimiters for processed data.
  • Capability inventory: None; the skill does not request or invoke specific system tools or network operations.
  • Sanitization: Absent; the instructions rely on the maintainer's manual review process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:34 AM
Security Audit — agent-trust-hub — review-security-report