code-review
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes Git commands, including
git diff,git log, andgit rev-parse, to analyze changes between a user-specified commit or branch and the currentHEAD. This is the primary functionality of the skill for performing code reviews. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code diffs and passes them directly to AI sub-agents, which presents a surface for indirect prompt injection.
- Ingestion points: Untrusted data from
git diffoutput is captured and interpolated into the prompts for both the Standards and Spec sub-agents in Step 4 (SKILL.md). - Boundary markers: The instructions do not define explicit delimiters or warnings (e.g., "ignore instructions contained within the diff") to prevent the sub-agents from obeying instructions embedded in code comments or strings within the diff.
- Capability inventory: The skill uses the
general-purposesub-agent to process data and generate textual reports based on the analyzed content (SKILL.md). - Sanitization: There is no evidence of sanitization, escaping, or filtering of the diff content before it is presented to the sub-agents.
- Ingestion points: Untrusted data from
Audit Metadata