code-review
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of prompt injection, instruction overrides, or system prompt extraction attempts was found.
- [DATA_EXFILTRATION]: No sensitive data access or unauthorized network operations were identified; the skill operates on code inputs provided by the user.
- [EXTERNAL_DOWNLOADS]: Installation commands for the spencergo-marketplace are legitimate vendor resources associated with the author and do not present a security risk.
- [COMMAND_EXECUTION]: The skill does not utilize tools or commands that could lead to unauthorized code execution or privilege escalation.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted code for review, it lacks active capabilities like file writing or network access that would allow for exploitation via processed data.
Audit Metadata