meta-reviewing-reviewing

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODEEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to ingest and analyze untrusted external data in the form of pull requests and source code.\n
  • Ingestion points: Code files and PR specifications defined in the review scope as described in SKILL.md.\n
  • Boundary markers: The skill lacks explicit instructions to use boundary markers or delimiters when processing untrusted code, although it mandates specific 'file:line' references for all findings which can mitigate accidental instruction following through grounded analysis.\n
  • Capability inventory: The skill consists entirely of instructional markdown and does not include any executable scripts or tools.\n
  • Sanitization: There are no instructions for sanitizing or escaping the content of the data being processed.\n- [NO_CODE]: The skill is composed entirely of markdown documentation and configuration files. It does not contain any executable scripts (e.g., Python, JavaScript) or binary files.\n- [EXTERNAL_DOWNLOADS]: The skill metadata references a JSON schema located in the vendor's official GitHub repository (agents-inc/cli).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 09:02 PM
Security Audit — agent-trust-hub — meta-reviewing-reviewing