code-review
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, such as code diffs and pull request descriptions, which could contain malicious instructions meant to subvert the agent's behavior.
- Ingestion points: The skill processes diffs, PR descriptions, and linked issues as mentioned in the 'Scope the review' section of SKILL.md.
- Boundary markers: The instructions lack explicit delimiters or specific warnings to ignore instructions embedded within the processed code or descriptions.
- Capability inventory: The skill suggests performing actions like opening files and potentially running code ("If you can run it, run it"), which increases the risk if the agent follows instructions hidden in a malicious diff.
- Sanitization: There are no instructions provided for sanitizing, escaping, or validating the untrusted content before it is interpolated into the agent's context.
Audit Metadata