skills/techygarg/lattice/review/Gen Agent Trust Hub

review

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing untrusted code deltas as primary input.
  • Ingestion points: Step 1 (Identify the Delta) uses git diff or user-provided files as the source of analyzed content.
  • Boundary markers: There are no delimited blocks or instructions provided to the agent to treat the code delta as passive data, increasing the risk of the agent following instructions embedded in the code.
  • Capability inventory: The skill performs file system operations including reading configuration from .lattice/config.yaml and appending logs to .lattice/reviews/review-log.md.
  • Sanitization: The workflow does not include steps to sanitize or validate the delta content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 03:19 AM
Security Audit — agent-trust-hub — review