blast-radius

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect injection as it processes external code changes. * Ingestion points: SKILL.md (Step 1) involves reading pull requests and commits. * Boundary markers: Absent. * Capability inventory: Includes file reading, searching, and script execution. * Sanitization: The skill advises stripping private data but does not include explicit instruction sanitization.
  • [DYNAMIC_EXECUTION]: The skill performs dynamic execution of local code for verification purposes. * Evidence: SKILL.md (Step 5) requires the agent to write and run a script or test that calls real code to prove safety facts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:20 AM
Security Audit — agent-trust-hub — blast-radius