caveman-review
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing external pull request data and incorporating summarized findings into local file paths and logs.
- Ingestion points: Pull request diffs and source code files provided by the user (SKILL.md).
- Boundary markers: Absent; the skill does not specify delimiters or guidelines to ignore instructions embedded within the processed code diffs.
- Capability inventory: File system write access to create files in
llmwiki/wiki/draft/cave/and modifyllmwiki/wiki/index.mdandllmwiki/wiki/log.md(SKILL.md). - Sanitization: No explicit sanitization or validation of the summarized strings (the
<ten>variable) is provided before use in file operations.
Audit Metadata