secure-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow to ingest and analyze external source code provided via the REPO_PATH input, which creates a potential vulnerability where malicious instructions embedded in the code under review could manipulate the agent's behavior.\n
  • Ingestion points: Source code files defined by the REPO_PATH input in SKILL.md.\n
  • Boundary markers: The instructions in SKILL.md and REFERENCE.md do not provide explicit delimiters or "ignore instructions" warnings to help the agent distinguish between its instructions and the content of the code under review.\n
  • Capability inventory: The skill's primary capabilities involve reading files and generating a markdown report as defined in SKILL.md; no dangerous capabilities such as direct system command execution or network exfiltration are present.\n
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the untrusted code content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:29 PM
Security Audit — agent-trust-hub — secure-code-review