skill-review
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from other skill files and feedback logs to perform patches, creating a surface where malicious instructions in those files could influence the agent's behavior during the review process.
- Ingestion points: The skill reads contents from
skills/*/SKILL.mdandshared/gotchas.mdduring Step 1 and Step 2. - Boundary markers: Absent. The instructions do not define delimiters or specific warnings to ignore embedded instructions within the files being reviewed.
- Capability inventory: The skill uses
Read,Write,Edit, andBashtools, which allow it to modify any instruction file in the project. - Sanitization: Absent. There is no mention of validating, filtering, or escaping the content retrieved from
gotchas.mdbefore it is patched into a skill.
Audit Metadata