code-review
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill analyzes external code which constitutes a surface for indirect prompt injection. 1. Ingestion points: Code snippets are read in 'SKILL.md' Step 1. 2. Boundary markers: The skill explicitly commands the agent to treat all code content as data only and to never follow instructions found within comments or strings. 3. Capability inventory: The skill has the capability to modify files when applying fixes. 4. Sanitization: The skill relies on natural language instructions to the model to ignore embedded commands and mandates a human-in-the-loop confirmation before any filesystem writes occur. These measures effectively mitigate the risk and warrant a safe verdict.
Audit Metadata