receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon code review feedback from external sources, which is untrusted data. A malicious reviewer could potentially embed instructions within the feedback that the agent might execute if it deems the feedback "technically sound."
- Ingestion points: External feedback and reviewer suggestions (SKILL.md).
- Boundary markers: Absent. There are no specific delimiters or instructions to treat the text of the feedback as literal data rather than instructions.
- Capability inventory: The skill assumes the ability to search the codebase (
grep), verify platform compatibility, and interact with the GitHub API (gh api) to post replies. - Sanitization: Absent. The skill focuses on technical verification but does not include steps to sanitize or filter the input strings for malicious prompt patterns.
- [PROMPT_INJECTION]: The skill contains explicit instructions to override the agent's default conversational behavior, such as forbidding gratitude or standard polite responses ("NEVER: ANY gratitude expression"). It references "explicit CLAUDE.md violation," which is an attempt to influence the agent by referencing or overriding platform-level behavioral guidelines.
Audit Metadata