skill-review

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from other skill files and feedback logs to perform patches, creating a surface where malicious instructions in those files could influence the agent's behavior during the review process.
  • Ingestion points: The skill reads contents from skills/*/SKILL.md and shared/gotchas.md during Step 1 and Step 2.
  • Boundary markers: Absent. The instructions do not define delimiters or specific warnings to ignore embedded instructions within the files being reviewed.
  • Capability inventory: The skill uses Read, Write, Edit, and Bash tools, which allow it to modify any instruction file in the project.
  • Sanitization: Absent. There is no mention of validating, filtering, or escaping the content retrieved from gotchas.md before it is patched into a skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 04:30 AM
Security Audit — agent-trust-hub — skill-review