sec-security-audit
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [SAFE]: The skill is composed of a single Markdown file containing instructions and process definitions. It does not ship with any executable code, scripts, or automated tools.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, specifically code repositories and system descriptions.
- Ingestion points: The skill processes external codebases and system descriptions as primary inputs for the audit process.
- Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore embedded instructions within the audited data to prevent the content from influencing the agent's behavior.
- Capability inventory: The skill requires the agent to perform code review, secret detection, and dependency scanning, all of which necessitate deep inspection of potentially malicious content.
- Sanitization: No sanitization or validation logic is specified for the input data before it is processed by the agent.
- [METADATA_POISONING]: There is a minor metadata inconsistency where the YAML frontmatter lists no dependencies or side effects, while the internal Markdown sections mention the use of scanner tools and side effects related to running those scanners. This appears to be a documentation oversight in an experimental skill rather than an attempt at deception.
Audit Metadata