performance-review-manager

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted feedback from various external sources.
  • Ingestion points: The skill reads peer feedback files from subdirectories (e.g., Q12026/employee-name/sources/) and self-assessment files which are authored by third parties.
  • Boundary markers: Absent. The instructions do not include boundary markers or delimiters (such as XML tags) to separate external content from internal logic, nor do they instruct the model to ignore instructions found within the ingested data.
  • Capability inventory: The skill uses filesystem read capabilities to gather assessment data and filesystem write capabilities to save the final manager report.
  • Sanitization: Absent. There is no instruction for the agent to validate, sanitize, or escape the content retrieved from external files before summarizing or quoting it.
  • [NO_CODE]: The skill consists exclusively of Markdown documentation and instructions and does not include any executable scripts or source code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 03:42 AM
Security Audit — agent-trust-hub — performance-review-manager