advpl-to-tlpp-migration
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is entirely instructional, providing a structured workflow and mapping rules for source code migration. All referenced concepts, such as namespaces and preprocessor directives, align with official TOTVS Protheus technical documentation (TDN).
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a processor for user-provided ADVPL source code. This represents a data ingestion surface where an attacker could theoretically embed instructions within code comments or string literals. However, the skill's instructions strictly guide the agent to perform specific structural transformations (e.g., mapping procedural functions to class methods and private variables to data properties), which naturally mitigates the risk of the agent deviating to follow instructions embedded within the code being analyzed.
Audit Metadata