advpl-code-review

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill analyzes untrusted ADVPL/TLPP source code, which creates a surface for indirect prompt injection. Malicious instructions could be hidden within comments or strings in the reviewed code to influence the agent's output. While the skill defines clear rules for detection, it does not explicitly instruct the agent to disregard instructions found within the code being analyzed. * Ingestion points: Source code provided by the user for analysis. * Boundary markers: No delimiters or instructions to ignore embedded commands are present in the review guidelines. * Capability inventory: The skill is restricted to generating text-based review reports and lacks file-system or network capabilities. * Sanitization: Input code is not sanitized for embedded instructions prior to analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 02:37 PM
Security Audit — agent-trust-hub — advpl-code-review