thermo-nuclear-review

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define a specialized persona and workflow for security auditing. The guidelines are focused on legitimate software development practices such as catching breaking changes, developer experience regressions, and feature gate leaks.
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface (Category 8) by instructing the agent to read pull request discussions and incorporate external findings from sources such as PR comments.
  • Ingestion points: Pull request and merge request discussions accessed via gh or glab CLI tools, and the code content of the branch diff.
  • Boundary markers: None specified in the instructions to delimit external comments from agent instructions.
  • Capability inventory: The skill mentions using gh and glab CLI tools to retrieve PR metadata. The YAML frontmatter includes disable-model-invocation: true, which restricts the model's autonomous tool usage.
  • Sanitization: The instructions include a reasoning-based check, directing the agent to 'evaluate them to determine if they are valid' before incorporating external findings into the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 05:33 PM
Security Audit — agent-trust-hub — thermo-nuclear-review