done
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of natural language instructions and does not include any scripts, external downloads, or requests for sensitive information.
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface: The skill instructs the agent to review uncommitted code, which is a source of untrusted data. This creates a surface where malicious instructions embedded in code comments could attempt to influence the agent's behavior.
- Ingestion points: Uncommitted code in the repository (logic for reviewing uncommitted changes).
- Boundary markers: No delimiters or specific 'ignore embedded instructions' warnings are present.
- Capability inventory: git commit, git rebase, git merge, worktree cleanup, and GitHub issue updates.
- Sanitization: No validation or sanitization of the code content is specified before the review process.
Audit Metadata