code-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local Python scripts that execute the
gitcommand-line utility via thesubprocessmodule. Specifically,pr_analyzer.pyandreview_report_generator.pyuse this to retrieve repository metadata, file statuses, and commit logs. These commands are executed using list-based arguments without a shell, which is a secure implementation practice for this functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external source code and pull request diffs, which constitutes an attack surface for indirect prompt injection.
- Ingestion points:
scripts/pr_analyzer.pyingests diff data via git commands;scripts/code_quality_checker.pyreads source code files using theread_file_contentfunction. - Boundary markers: The skill does not use explicit delimiters to isolate untrusted code content from its internal logic, though it produces structured output (JSON/Markdown).
- Capability inventory: The skill has capabilities to execute the
gitbinary and perform file read/write operations. - Sanitization: The scripts apply regular expression pattern matching to identify risks (e.g., secrets, SQL injection signatures) rather than executing or interpreting the code content.
Audit Metadata