strix-review
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and acts upon instructions contained in comments provided by humans via the 'strix' tool state file.
- Ingestion points: The agent ingests external data from
.git/strix/comments.jsonusing thestrix comment list --jsoncommand. - Boundary markers: The instructions do not define clear boundaries or provide warnings to the agent to treat comment text strictly as data and ignore any embedded instructions.
- Capability inventory: The agent is empowered to execute
strixCLI commands, modify files in the repository to 'fix' issues, and create git commits. - Sanitization: There is no evidence of sanitization, validation, or filtering of the comment content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill relies on the
strixCLI to perform operations such as listing, adding, removing, and clearing comments. While this is the intended purpose, it involves direct execution of shell commands provided by the skill instructions.
Audit Metadata