review-work
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The specialist role
qa-cli-expertis directed to identify and run shell commands such as test runners, linters, and type checkers from the local repository context. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted code changes and diffs from the local repository.
- Ingestion points: Changed files and
git diffoutput retrieved via shell commands in Phase 1. - Boundary markers: The specialist prompts in Phase 2 do not include explicit instructions to disregard malicious directives embedded in comments or strings within the code being reviewed.
- Capability inventory: The skill has access to shell execution and subagent spawning across all phases.
- Sanitization: Content from the files is processed directly without escaping or validation.
Audit Metadata