orchestrate-review

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes shell commands using the exec function to perform git add and git commit operations. While these are used for tracking review progress, direct shell execution is a sensitive capability.
  • [INDIRECT_PROMPT_INJECTION]: The skill reviews external code files by interpolating their content directly into prompts for sub-agents. This creates an attack surface where malicious instructions inside a codebase could manipulate the review outcome or sub-agent behavior.
  • Ingestion points: The files list containing content from changed source code files is passed to the reviewer agents via the Task prompt template.
  • Boundary markers: The prompt template does not use specific delimiters or instructions to the LLM to ignore potentially malicious embedded instructions within the provided file content.
  • Capability inventory: The skill has access to spawn parallel agents (Task), modify files (Edit), and execute shell commands (exec).
  • Sanitization: There is no evidence of sanitization, filtering, or escaping of the file content before it is processed by the sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:15 AM
Security Audit — agent-trust-hub — orchestrate-review