review-work

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The specialist role qa-cli-expert is directed to identify and run shell commands such as test runners, linters, and type checkers from the local repository context.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted code changes and diffs from the local repository.
  • Ingestion points: Changed files and git diff output retrieved via shell commands in Phase 1.
  • Boundary markers: The specialist prompts in Phase 2 do not include explicit instructions to disregard malicious directives embedded in comments or strings within the code being reviewed.
  • Capability inventory: The skill has access to shell execution and subagent spawning across all phases.
  • Sanitization: Content from the files is processed directly without escaping or validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 12:56 PM
Security Audit — agent-trust-hub — review-work