code-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes untrusted source code and git diffs, creating a surface where malicious instructions embedded in a pull request could influence the AI agent's evaluation. * Ingestion points:
scripts/pr_analyzer.pyandscripts/code_quality_checker.pyread files and git data from the target repository. * Boundary markers: Absent; analysis findings are output as structured text or markdown without markers to separate untrusted content from tool metadata. * Capability inventory: The skill usessubprocess.runto execute git commands and local analysis scripts. * Sanitization: Absent; the tool does not filter or escape analyzed code snippets to prevent agent manipulation. - [COMMAND_EXECUTION]: The skill interacts with the local system by executing Git CLI commands and internal analysis scripts through
subprocess.run. These calls are constructed safely using list-based arguments without shell=True, minimizing risks from malformed repository paths or branch names.
Audit Metadata