spine-review
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious instructions, obfuscation, or unauthorized data exfiltration patterns were detected. The skill's functionality is limited to analyzing a local codebase and providing architectural feedback.
- [PROMPT_INJECTION]: The skill processes untrusted code files (indirect prompt injection surface) as part of its primary review function. While this presents an inherent surface for adversarial instructions in the analyzed code to influence the agent, the skill instructions are focused on analytical tasks and do not demonstrate unsafe handling of the data.
- Ingestion points: Codebase files including route definitions, middleware, and models (SKILL.md Step 1).
- Boundary markers: Absent in the instructions.
- Capability inventory: Bash, Write, Edit, TodoWrite (SKILL.md frontmatter).
- Sanitization: Not specified.
Audit Metadata