requesting-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The code reviewer subagent is instructed to run shell commands such as git diff using placeholders {BASE_SHA} and {HEAD_SHA} from code-reviewer.md. If these commit identifiers are sourced from untrusted inputs or manipulated to include shell metacharacters (e.g., using semicolons or pipes), it could lead to arbitrary command execution on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external content via the {PLAN_OR_REQUIREMENTS} placeholder to provide context for the review. This creates a vulnerability where instructions embedded within requirements documents or implementation plans could influence the reviewer's behavior or cause it to ignore its safety checklist.
  • Ingestion points: {PLAN_OR_REQUIREMENTS} and {WHAT_WAS_IMPLEMENTED} in code-reviewer.md.
  • Boundary markers: Absent.
  • Capability inventory: Execution of git commands and generating textual analysis.
  • Sanitization: No evidence of escaping or filtering for the interpolated context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — requesting-code-review