cross-review
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests pull request diffs and passes them to an LLM for adversarial review. This creates a surface where an attacker could embed malicious instructions in the code or comments to trick the reviewer. This is a low-severity risk common to AI review tools. The skill robustly mitigates this by using read-only toolsets for the reviewer and a mandatory fingerprinting guard (reviewer-guard) that invalidates the review if any changes are detected in the file system.
- [COMMAND_EXECUTION]: The mutation testing component of the skill executes a user-provided test command locally on the developer's machine. This is a standard and required feature for mutation testing tools and is used to verify that the test suite is capable of detecting specific code defects.
- [DYNAMIC_EXECUTION]: The skill dynamically generates and executes code stubs at runtime during the mutation testing process. These stubs are used to replace portions of the source code with inert implementations in a temporary directory to observe the reaction of the test suite.
Audit Metadata