explain-code
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external code provided by the user, which presents a surface for indirect prompt injection attacks.
- Ingestion points: The agent reads user-provided file content, diffs, or code snippets (SKILL.md).
- Boundary markers: The instructions do not specify any delimiters or explicit warnings for the agent to ignore instructions that might be embedded within the code being explained.
- Capability inventory: The skill frontmatter includes
disable-model-invocation: true, which limits the agent's ability to call external tools or perform actions beyond text generation, significantly reducing the potential impact of an injection. - Sanitization: There are no instructions for sanitizing or escaping the content of the code snippets before they are processed by the agent.
Audit Metadata