ai-code-walkthrough
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted code blocks and diffs, representing an indirect prompt injection surface. The risk is minimized by explicit safety rules in SKILL.md that prevent the agent from executing dynamic code or exposing secrets. (Ingestion points: User-provided code blocks, file paths, and git diffs; Boundary markers: None; Capability inventory: File reading, git diff execution; Sanitization: None).
- [COMMAND_EXECUTION]: A provided utility script, scripts/extract-diff-context.sh, allows for reading git diffs with context. It contains validation for user-provided arguments, such as context line limits and path traversal checks, ensuring it operates safely on local files.
- [SAFE]: The skill does not perform network operations, exfiltrate data, or use obfuscation techniques. Its design is focused on safe, read-only code analysis.
Audit Metadata