adverse-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted project source code as part of its core review function, which represents a vulnerability surface. It mitigates this by instructing subagents to treat the ingested code strictly as data and to ignore any directives found within it. (Ingestion points:
scripts/collect.mjsreads the target repository; Boundary markers:scripts/prompts/round1.txtcontains explicit 'ignore instructions' directives; Capability inventory: subagents return structured JSON for synthesis into local reports; Sanitization: no character-level escaping is performed on the source block). - [COMMAND_EXECUTION]: The skill executes local helper scripts using the Node.js runtime to collect project data and synthesize the final review report.
- [DYNAMIC_EXECUTION]: The helper scripts use standard ESM imports to load business logic from relative paths within the parent project directory.
Audit Metadata