skills/buiducnhat/cobrew/review/Gen Agent Trust Hub

review

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data in the form of git diffs and full file contents from the workspace. This creates a surface for indirect prompt injection where malicious instructions embedded in comments or code could attempt to influence the agent's review verdict.
  • Ingestion points: git diff, git diff --cached, and full modified files read during the context gathering step.
  • Boundary markers: The skill does not explicitly instruct the agent to use delimiters or ignore instructions found within the code being reviewed.
  • Capability inventory: The agent can read files and execute git commands.
  • Sanitization: No specific sanitization or escaping of the ingested code content is defined.
  • [COMMAND_EXECUTION]: The workflow involves running quality checks such as linting, type checking, and tests. While these are standard development practices, they involve executing commands that may be defined within the local project configuration (e.g., scripts in a package.json or Makefile).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:56 AM
Security Audit — agent-trust-hub — review