show-me-the-code
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill instructs the agent to process and format code changes from external requests.
- Ingestion points: User-provided code snippets or file modification requests mentioned in SKILL.md.
- Boundary markers: Absent. The skill does not instruct the agent to use delimiters or ignore instructions embedded within the code being diffed.
- Capability inventory: None. The skill is limited to output formatting and does not involve tool usage or script execution.
- Sanitization: Absent. The skill does not define methods for validating or escaping the input code content.
Audit Metadata