audit-review
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as an instructional template for defensive security activities, specifically auditing pull requests and features for logical faults and security vulnerabilities.
- [SAFE]: No hardcoded credentials, malicious remote downloads, or unauthorized execution patterns were found in the skill content.
- [SAFE]: The instructions explicitly guide the agent to identify security-critical issues such as 'credential/secret exposure in logs or error messages' and 'injection risks'.
- [PROMPT_INJECTION]: The skill inherently processes untrusted code (PRs, features) as its primary ingestion point, which constitutes an indirect prompt injection surface. This is a risk factor associated with the intended primary purpose of the skill.
- Ingestion points: Audited code changes and pull request metadata provided for analysis.
- Boundary markers: Not specified in the workflow instructions to isolate untrusted data from the agent's instructions.
- Capability inventory: Primarily static reasoning and reporting; mentions manual runtime execution but provides no automated tools or scripts.
- Sanitization: No sanitization or validation of the input code is defined.
Audit Metadata