review

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks as it ingests and processes untrusted data from git diffs and repository files without explicit boundary markers.
  • Ingestion points: Ingests data through git diff and reading repository files like docs/onboarding/project-memory.md as defined in SKILL.md.
  • Boundary markers: No delimiters or instructions are provided to the agent to ignore potentially malicious instructions embedded within the code diffs.
  • Capability inventory: The skill utilizes file system reads and standard git operations; no high-risk capabilities such as network exfiltration or arbitrary code execution are defined.
  • Sanitization: There is no evidence of input validation, escaping, or sanitization of the content being reviewed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 08:08 AM
Security Audit — agent-trust-hub — review