review-code

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to maintain its operational environment. Specifically, it creates and manages a dedicated scratchpad directory (.workflow/.scratchpad/) for storing temporary state files, review findings, and the final Markdown report. This activity is restricted to a localized, workflow-specific path.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to read and process external, untrusted source code files. Code snippets from these files are captured and stored in the review state, which is then passed to the agent orchestrator in subsequent steps. While this is a standard operational requirement for a code review tool, it creates a vector where malicious instructions in the analyzed code could potentially influence the agent's behavior.
  • Ingestion points: Source code files are read using the Glob and Read tools in phases/actions/action-collect-context.md and phases/actions/action-deep-review.md.
  • Boundary markers: The orchestrator.md file structures its prompt using clear headers (e.g., [STATE], [ACTION]), but it does not incorporate explicit delimiter-based warnings to the agent to ignore instructions embedded within the code snippets in the state data.
  • Capability inventory: Across its scripts, the skill maintains access to Agent, Bash, Read, and Write tools.
  • Sanitization: The skill does not apply specific sanitization or escaping techniques to the captured code snippets before including them in the execution context of the orchestrator agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:11 AM