review-changes

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external code changes and execution paths.
  • Ingestion points: Data is ingested through the detect_changes_tool and get_affected_flows_tool in SKILL.md.
  • Boundary markers: No delimiters are defined to isolate untrusted code content from instructions.
  • Capability inventory: Actions are limited to analysis and reporting; no file-write, network-send, or command-execution capabilities are specified.
  • Sanitization: No sanitization of the input code is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:37 PM
Security Audit — agent-trust-hub — review-changes