staff-engineer-review

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data such as pull request descriptions and code changes. \n
  • Ingestion points: Input fields defined in SKILL.md include 'PR Description', 'Code Changes', and 'Additional Context'. \n
  • Boundary markers: The skill instructions do not explicitly mandate the use of delimiters or 'ignore' instructions for the processed content. \n
  • Capability inventory: The skill contains only markdown instructions and no executable scripts, limiting the potential impact of an injection. \n
  • Sanitization: No automated sanitization of ingested text is specified, as the agent is expected to perform manual evaluation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:07 PM
Security Audit — agent-trust-hub — staff-engineer-review