review-security-report
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of markdown instructions for human-in-the-loop security triage. It does not include scripts, binaries, or automated tool configurations.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data (security reports, proof-of-concept code, and bug bounty submissions). This inherent attack surface is noted, although the skill focuses on providing analytical guidelines rather than automated processing logic.
- Ingestion points: External vulnerability reports, comments, and proof-of-concept files (SKILL.md).
- Boundary markers: Absent; the skill does not define specific delimiters for processed data.
- Capability inventory: None; the skill does not request or invoke specific system tools or network operations.
- Sanitization: Absent; the instructions rely on the maintainer's manual review process.
Audit Metadata