adverse-review

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted project source code as part of its core review function, which represents a vulnerability surface. It mitigates this by instructing subagents to treat the ingested code strictly as data and to ignore any directives found within it. (Ingestion points: scripts/collect.mjs reads the target repository; Boundary markers: scripts/prompts/round1.txt contains explicit 'ignore instructions' directives; Capability inventory: subagents return structured JSON for synthesis into local reports; Sanitization: no character-level escaping is performed on the source block).
  • [COMMAND_EXECUTION]: The skill executes local helper scripts using the Node.js runtime to collect project data and synthesize the final review report.
  • [DYNAMIC_EXECUTION]: The helper scripts use standard ESM imports to load business logic from relative paths within the parent project directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:32 PM
Security Audit — agent-trust-hub — adverse-review