requesting-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The code reviewer subagent is instructed to run shell commands such as
git diffusing placeholders{BASE_SHA}and{HEAD_SHA}fromcode-reviewer.md. If these commit identifiers are sourced from untrusted inputs or manipulated to include shell metacharacters (e.g., using semicolons or pipes), it could lead to arbitrary command execution on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external content via the
{PLAN_OR_REQUIREMENTS}placeholder to provide context for the review. This creates a vulnerability where instructions embedded within requirements documents or implementation plans could influence the reviewer's behavior or cause it to ignore its safety checklist. - Ingestion points:
{PLAN_OR_REQUIREMENTS}and{WHAT_WAS_IMPLEMENTED}incode-reviewer.md. - Boundary markers: Absent.
- Capability inventory: Execution of git commands and generating textual analysis.
- Sanitization: No evidence of escaping or filtering for the interpolated context.
Audit Metadata