vanity-engineering-review

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown files providing instructions, detection patterns, and templates. It does not include any Python, Node.js, or shell scripts, eliminating the risk of direct malicious code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data in the form of external codebases, pull requests, and architecture proposals. While this constitutes an attack surface for indirect prompt injection (where malicious instructions are hidden in analyzed code), the skill does not define any high-risk tools or capabilities—such as network exfiltration or file system modifications—that could be abused if an injection were successful.
  • [SAFE]: No evidence of prompt injection, obfuscation, privilege escalation, or persistence mechanisms was found. The instructions are transparent and strictly focused on the stated diagnostic purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:52 PM
Security Audit — agent-trust-hub — vanity-engineering-review