review-code
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to maintain its operational environment. Specifically, it creates and manages a dedicated scratchpad directory (.workflow/.scratchpad/) for storing temporary state files, review findings, and the final Markdown report. This activity is restricted to a localized, workflow-specific path. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to read and process external, untrusted source code files. Code snippets from these files are captured and stored in the review state, which is then passed to the agent orchestrator in subsequent steps. While this is a standard operational requirement for a code review tool, it creates a vector where malicious instructions in the analyzed code could potentially influence the agent's behavior.
- Ingestion points: Source code files are read using the
GlobandReadtools inphases/actions/action-collect-context.mdandphases/actions/action-deep-review.md. - Boundary markers: The
orchestrator.mdfile structures its prompt using clear headers (e.g.,[STATE],[ACTION]), but it does not incorporate explicit delimiter-based warnings to the agent to ignore instructions embedded within the code snippets in the state data. - Capability inventory: Across its scripts, the skill maintains access to
Agent,Bash,Read, andWritetools. - Sanitization: The skill does not apply specific sanitization or escaping techniques to the captured code snippets before including them in the execution context of the orchestrator agent.
Audit Metadata