requesting-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest external data, specifically git diffs and plan files, and pass this content to a sub-agent for evaluation. This creates a surface where malicious instructions embedded in the code or documents could attempt to influence the reviewer agent's behavior.
- Ingestion points: The output of git diff commands and local documentation files like docs/opencode-skills/plans/deployment-plan.md.
- Boundary markers: Absent; the instructions do not provide delimiters or warnings for the sub-agent to ignore instructions contained within the analyzed data.
- Capability inventory: The skill uses the Task tool to dispatch agents and shell execution for git operations.
- Sanitization: Absent; there is no evidence of filtering or escaping logic for the ingested content.
- [COMMAND_EXECUTION]: The skill requires the execution of shell commands, specifically git sub-commands (git rev-parse, git log, git diff), to identify and extract change sets for the review process.
Audit Metadata