code-review

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection because it ingests and processes untrusted data from external code files and git diffs.
  • Ingestion points: Reads code changes via git diff or specific files/directories provided in $ARGUMENTS, as well as configuration from .claude/rules/ (SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" headers for the content being reviewed.
  • Capability inventory: The skill has access to powerful tools including Bash, Task, Read, Grep, and Glob, which allow for shell command execution and file system interaction (SKILL.md).
  • Sanitization: There is no evidence of sanitization or filtering of the external code content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 01:21 AM
Security Audit — agent-trust-hub — code-review