skills/pubx-ai/skills/adcp-review/Gen Agent Trust Hub

adcp-review

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to process untrusted data from pull requests, diffs, and commits, which introduces an indirect prompt injection surface. The instructions explicitly direct the agent to ignore instructions found within this data and to treat them as warnings. Ingestion points include PR metadata and code comments in SKILL.md. The skill has no file-write or shell capabilities, limiting the potential impact of an injection.
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation from docs.adcontextprotocol.org to verify protocol compliance. It retrieves a machine-readable index and specific specification pages to ensure accuracy. This is a functional requirement for the skill to track regular protocol updates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 02:21 PM
Security Audit — agent-trust-hub — adcp-review