tech-debt
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill is entirely composed of markdown instructions and documentation templates.
- [NO_CODE]: The skill does not contain any scripts, source code, binary executables, or external library dependencies, significantly reducing the attack surface.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for the agent to process user-provided descriptions of legacy code and technical debt. While this creates an ingestion point for untrusted data, the agent lacks any sensitive capabilities (such as file writing, network access, or command execution) that could be leveraged if malicious instructions were embedded in the user's input.
Audit Metadata