mcp-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The review-code prompt template in SKILL.md is susceptible to indirect prompt injection because it interpolates untrusted code diffs directly into the prompt. 1. Ingestion points: diff parameter in review-code prompt template. 2. Boundary markers: Absent. 3. Capability inventory: search_files (globbing) and run_query (SQL). 4. Sanitization: Absent.
- [COMMAND_EXECUTION]: The run_query tool example uses a weak case-insensitive prefix check for SELECT statements, which can be bypassed to execute unauthorized SQL commands if the template is used in production.
Audit Metadata