orchestrate-review
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes shell commands using the
execfunction to performgit addandgit commitoperations. While these are used for tracking review progress, direct shell execution is a sensitive capability. - [INDIRECT_PROMPT_INJECTION]: The skill reviews external code files by interpolating their content directly into prompts for sub-agents. This creates an attack surface where malicious instructions inside a codebase could manipulate the review outcome or sub-agent behavior.
- Ingestion points: The
fileslist containing content from changed source code files is passed to the reviewer agents via the Task prompt template. - Boundary markers: The prompt template does not use specific delimiters or instructions to the LLM to ignore potentially malicious embedded instructions within the provided file content.
- Capability inventory: The skill has access to spawn parallel agents (
Task), modify files (Edit), and execute shell commands (exec). - Sanitization: There is no evidence of sanitization, filtering, or escaping of the file content before it is processed by the sub-agents.
Audit Metadata