skills/toy-crane/skills/human-review/Gen Agent Trust Hub

human-review

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted repository data, constituting an indirect prompt injection surface.
  • Ingestion points: Ingests repository diffs, specifications, and project instructions as defined in SKILL.md.
  • Boundary markers: Lacks explicit text delimiters for untrusted content, using logical verification steps instead.
  • Capability inventory: Read-access to repository files, write-access for temporary artifacts, and the ability to serve/open HTML files.
  • Sanitization: Instructions mandate the redaction of secrets and personal data from the evidence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 06:07 AM
Security Audit — agent-trust-hub — human-review