writing-code
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill audits user-provided code snippets, creating an attack surface for indirect prompt injection.
- Ingestion points: User-provided code snippets provided during auditing tasks (SKILL.md, evals.json).
- Boundary markers: Absent; there are no specific instructions or delimiters used to prevent the agent from following instructions embedded in the code being audited.
- Capability inventory: None; the skill does not request or use tools for network access, file system modification, or process execution.
- Sanitization: Absent; the skill does not perform validation or filtering on the code content it analyzes.
Audit Metadata