multiplayer-review
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted project files to generate code reviews, creating an attack surface for indirect prompt injection.\n
- Ingestion points: The agent is instructed to scan all project files to identify networking frameworks, architecture, and logic during Phase 1.\n
- Boundary markers: The skill does not define delimiters or provide instructions to the agent to distinguish between its own logic and the data read from files.\n
- Capability inventory: The skill is primarily diagnostic and generates text-based reports. It also logs telemetry to a local file (
skill-telemetry.md), but lacks capabilities for arbitrary command execution or network exfiltration.\n - Sanitization: Content from the analyzed codebase is not sanitized before processing.
Audit Metadata