requesting-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use
git rev-parseandgit diffto identify changes and generate summaries for review. These are standard developer operations performed on the local repository state.\n- [INDIRECT_PROMPT_INJECTION]: The code review template (code-reviewer.md) ingests implementation details, plans, and git diff output. There are no explicit instructions or delimiters to prevent the agent from being influenced by instructions that might be present in the code being reviewed.\n - Ingestion points: Placeholders in
code-reviewer.md({WHAT_WAS_IMPLEMENTED},{PLAN_OR_REQUIREMENTS},{DESCRIPTION}) and the output ofgit diffcommands.\n - Boundary markers: Absent; the template does not contain specific instructions to ignore malicious directives found within the data being processed.\n
- Capability inventory: The skill is capable of reading repository files and commit history using
git.\n - Sanitization: None; input data is interpolated directly into the review prompt.
Audit Metadata