code-health
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from source code and coverage reports, which constitutes a surface for indirect prompt injection attacks. • Ingestion points: Repository source files and coverage data files (e.g., LCOV, Cobertura). • Boundary markers: There are no explicit delimiters or instructions for the agent to ignore embedded commands within the analyzed files. • Capability inventory: The agent retrieves analysis results through tools like get_health and get_risk. • Sanitization: No specific sanitization or filtering of the input data is documented.
Audit Metadata