intent-changes
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands (git config user.name or echo $USER) to determine the reviewer's identity for the change proposals.
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from existing design documents to generate and apply change proposals, creating an attack surface for indirect prompt injection. Ingestion points: Source documents are read during the propose and finalize steps. Boundary markers: No specific delimiters or ignore instructions are defined for content read from files. Capability inventory: The agent can write to the .reviews/ directory and update source files in the project. Sanitization: No sanitization or validation of source document content is specified before processing.
Audit Metadata