audit-review

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as an instructional template for defensive security activities, specifically auditing pull requests and features for logical faults and security vulnerabilities.
  • [SAFE]: No hardcoded credentials, malicious remote downloads, or unauthorized execution patterns were found in the skill content.
  • [SAFE]: The instructions explicitly guide the agent to identify security-critical issues such as 'credential/secret exposure in logs or error messages' and 'injection risks'.
  • [PROMPT_INJECTION]: The skill inherently processes untrusted code (PRs, features) as its primary ingestion point, which constitutes an indirect prompt injection surface. This is a risk factor associated with the intended primary purpose of the skill.
  • Ingestion points: Audited code changes and pull request metadata provided for analysis.
  • Boundary markers: Not specified in the workflow instructions to isolate untrusted data from the agent's instructions.
  • Capability inventory: Primarily static reasoning and reporting; mentions manual runtime execution but provides no automated tools or scripts.
  • Sanitization: No sanitization or validation of the input code is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 11:28 PM
Security Audit — agent-trust-hub — audit-review