code-simplify
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source code and test files, which serves as a potential vector for indirect prompt injection.
- Ingestion points: The skill reads target files, caller functions, and test suites in
SKILL.md(Step 1) using theRead,Glob, andGreptools. - Boundary markers: There are no explicit delimiters or "ignore instructions" warnings defined for the content read from external files, which could allow malicious comments in the code to influence the agent's behavior.
- Capability inventory: The skill has the ability to modify the filesystem using
EditandWrite, and can execute shell commands via theBashtool to run tests, type checks, or build steps inSKILL.md(Step 5). - Sanitization: The skill does not perform sanitization or validation of the ingested code content before it is processed or used as triggers for shell-based verification commands.
Audit Metadata