fix-types
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing external Python source code and mypy error logs.
- Ingestion points: Python source code files and terminal output from the 'uv run mypy' command as described in SKILL.md.
- Boundary markers: The skill does not define specific delimiters to separate untrusted code content from its core instructions.
- Capability inventory: The skill utilizes the Bash tool for running type checks and possesses the capability to modify project files to apply fixes.
- Sanitization: No data validation, escaping, or filtering is applied to the code or tool output before analysis.
- Mitigation: The primary safeguard is a strict human-in-the-loop requirement, ensuring no fixes are applied without explicit user review and approval.
Audit Metadata