requesting-code-review
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The template in
code-reviewer.mdconstructs shell commands (e.g.,git diff {BASE_SHA}..{HEAD_SHA}) using string interpolation. This creates a risk of command injection if the variables are populated with data from untrusted sources—such as a pull request description or externally suggested commit SHAs—that contain shell metacharacters. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its handling of untrusted data.
- Ingestion points: External data is ingested through placeholders
{WHAT_WAS_IMPLEMENTED},{PLAN_OR_REQUIREMENTS}, and{DESCRIPTION}incode-reviewer.md. - Boundary markers: No delimiters (e.g., XML tags, triple quotes) or 'ignore embedded instructions' warnings are used to isolate these inputs from the agent's core instructions.
- Capability inventory: The subagent is authorized to execute shell commands (
git) and access the filesystem, providing a high-impact target for successful injection. - Sanitization: There is no evidence of sanitization, escaping, or validation of placeholder content before it is interpolated into the prompt.
Audit Metadata