code-review-burntsushi

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted user-provided content (code diffs and files), creating a surface for indirect prompt injection.\n
  • Ingestion points: Untrusted data enters the agent context through user-provided code for review as described in SKILL.md.\n
  • Boundary markers: The instructions do not define clear delimiters or markers to separate untrusted code content from the agent's instructions, nor do they include warnings to ignore instructions potentially embedded in the data.\n
  • Capability inventory: The skill's instructions are limited to generating textual review findings and do not include high-risk capabilities such as network access, file system writes, or subprocess execution.\n
  • Sanitization: No input validation or sanitization is specified for the code content before it is processed by the agent.\n- [NO_CODE]: This skill consists entirely of instructional markdown files (SKILL.md and REFERENCE.md) and does not include any executable scripts or binary files, which inherently limits its ability to perform direct malicious actions like command execution or persistence.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:30 PM
Security Audit — agent-trust-hub — code-review-burntsushi