reviewing-state-management

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWSAFE
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill's primary purpose is to review external data (code), creating a surface for indirect prompt injection where instructions embedded in code files could attempt to influence the agent's reasoning.
  • Ingestion points: Files accessed via the Read and Grep tools.
  • Boundary markers: None identified in the skill definition.
  • Capability inventory: Read and Grep (limited to local filesystem read access).
  • Sanitization: None identified; the agent relies on its internal logic to interpret the data.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials or unauthorized network operations were detected. The tools are limited to local read-only operations.
  • [Unverifiable Dependencies] (SAFE): The skill does not define external package dependencies or remote script downloads.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 01:10 PM