code-review
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection because it ingests and processes untrusted data from external code files and git diffs.
- Ingestion points: Reads code changes via
git diffor specific files/directories provided in$ARGUMENTS, as well as configuration from.claude/rules/(SKILL.md). - Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" headers for the content being reviewed.
- Capability inventory: The skill has access to powerful tools including
Bash,Task,Read,Grep, andGlob, which allow for shell command execution and file system interaction (SKILL.md). - Sanitization: There is no evidence of sanitization or filtering of the external code content before it is processed by the agent.
Audit Metadata