skills/quantipixels/skills/simplify/Gen Agent Trust Hub

simplify

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-provided code targets, creating a potential surface for indirect prompt injection where malicious instructions embedded in the code could attempt to manipulate the agent's review findings.\n
  • Ingestion points: The skill ingests a 'target supplied by the user' or code from an 'upstream merge-base diff' (SKILL.md).\n
  • Boundary markers: The instructions provide clear functional boundaries ('read-only maintainability review') but do not implement technical delimiters or specific instructions to ignore embedded prompts within the code targets.\n
  • Capability inventory: The skill is strictly limited to read-only analysis and is explicitly prohibited from changing code, tests, documentation, or state (SKILL.md).\n
  • Sanitization: There is no evidence of specific sanitization or filtering logic applied to the external code targets before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 11:01 PM
Security Audit — agent-trust-hub — simplify