skills/corvalis-llc/crow-stack/review/Gen Agent Trust Hub

review

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local git commands such as git diff, git add, and git commit. These are used to identify changes in the project, present them for review, and persist approved modifications to the repository.
  • [DATA_EXFILTRATION]: While the skill reads source code and git differences, this data remains within the local agent environment. No network operations or external data exfiltration patterns were observed.
  • [PROMPT_INJECTION]: The skill processes untrusted code through git diff outputs, creating an indirect prompt injection surface.
  • Ingestion points: Git diff outputs from files being reviewed.
  • Boundary markers: None explicitly mentioned in the prompt interpolation logic.
  • Capability inventory: Filesystem access via git, subagent execution.
  • Sanitization: The skill's primary function is to perform security analysis on the ingested code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:36 AM
Security Audit — agent-trust-hub — review