code-review

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes Git commands, including git diff, git log, and git rev-parse, to analyze changes between a user-specified commit or branch and the current HEAD. This is the primary functionality of the skill for performing code reviews.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code diffs and passes them directly to AI sub-agents, which presents a surface for indirect prompt injection.
    • Ingestion points: Untrusted data from git diff output is captured and interpolated into the prompts for both the Standards and Spec sub-agents in Step 4 (SKILL.md).
    • Boundary markers: The instructions do not define explicit delimiters or warnings (e.g., "ignore instructions contained within the diff") to prevent the sub-agents from obeying instructions embedded in code comments or strings within the diff.
    • Capability inventory: The skill uses the general-purpose sub-agent to process data and generate textual reports based on the analyzed content (SKILL.md).
    • Sanitization: There is no evidence of sanitization, escaping, or filtering of the diff content before it is presented to the sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — code-review