code-reviewer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local Python scripts that execute the git command-line utility via the subprocess module. Specifically, pr_analyzer.py and review_report_generator.py use this to retrieve repository metadata, file statuses, and commit logs. These commands are executed using list-based arguments without a shell, which is a secure implementation practice for this functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external source code and pull request diffs, which constitutes an attack surface for indirect prompt injection.
  • Ingestion points: scripts/pr_analyzer.py ingests diff data via git commands; scripts/code_quality_checker.py reads source code files using the read_file_content function.
  • Boundary markers: The skill does not use explicit delimiters to isolate untrusted code content from its internal logic, though it produces structured output (JSON/Markdown).
  • Capability inventory: The skill has capabilities to execute the git binary and perform file read/write operations.
  • Sanitization: The scripts apply regular expression pattern matching to identify risks (e.g., secrets, SQL injection signatures) rather than executing or interpreting the code content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:43 PM
Security Audit — agent-trust-hub — code-reviewer