adversarial-review
Fail
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use a specific mode to suppress security prompts.
- Evidence: In the 'Permission Mode' section, the instructions state to 'always pass
mode: "bypassPermissions"' to avoid 'permission prompts during unattended execution.' - This directive bypasses standard user-consent workflows and privilege controls within the agent execution environment.
- [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection through its primary function.
- Ingestion points: The skill accepts a
<file-or-directory>argument and reads the content of these files for review. - Boundary markers: Absent. There are no instructions or delimiters provided to ensure the agent ignores malicious commands that might be embedded in the code files being analyzed.
- Capability inventory: The skill utilizes the Agent tool to spawn sub-agents and integrates with multiple review and validation tools.
- Sanitization: Absent. The skill performs no validation or escaping of the external file content before it is processed by the model.
Recommendations
- AI detected serious security threats
Audit Metadata