nutmeg-review
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided code, data pipelines, and documentation to perform its reviews. This architecture creates a surface for indirect prompt injection, where malicious instructions embedded within the code or data being analyzed could potentially manipulate the behavior of the specialized sub-agents.
- Ingestion points: The skill reads external file paths provided by the user and the user profile file
.nutmeg.user.md. - Boundary markers: The prompt templates for the
data-reviewerandchart-revieweragents do not define explicit delimiters or instructions to ignore potential commands embedded in the code under review. - Capability inventory: The skill and its sub-agents have access to potentially powerful tools, including
Agent(for spawning sub-tasks),Bash(for command execution), andWrite(for file modifications). - Sanitization: There is no evidence of sanitization, filtering, or escaping of the code content before it is interpolated into the prompts for the specialized reviewer agents.
Audit Metadata