code-reviewer
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses dynamic context injection (the
!command syntax) inSKILL.mdto executecatcommands at initialization. This is used to load shared protocol files (UX, validation, tool efficiency) and local configuration files (.production-grade.yaml) from the project root. These operations are limited to reading local files and do not incorporate unvalidated user input into the shell commands. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because its primary function is to ingest and analyze untrusted content from the repository, such as source code comments, requirement documents, and architecture specifications. An attacker could embed malicious instructions in these files to attempt to influence the generated review report or code patches.
- Ingestion points: Reads files across the
services/,libs/,frontend/,docs/architecture/, andtests/directories. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when the agent processes the content of the analyzed files.
- Capability inventory: The skill has file-read capabilities across the project and file-write capabilities restricted to the
.forgewright/code-reviewer/directory. - Sanitization: No specific content filtering or sanitization of the input code/docs is performed before analysis.
Audit Metadata