changes-review-loop

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains operational constraints to ignore platform-specific mode-switch instructions, which are benign compatibility notes. Static detection flags for concealment are false positives; the protocol explicitly mandates user approval for workflow deviations, step-by-step reporting, and direct user escalation if the loop fails to converge.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect injection by ingesting code diffs and project metadata. These findings do not escalate the verdict as the behavior is required for the skill's primary function.
  • Ingestion points: Git diff output, project config files, and reference documentation (SKILL.md).
  • Boundary markers: No explicit data delimiters are defined for diff ingestion.
  • Capability inventory: File system access, git command execution, and invocation of secondary skills for fixing and review (SKILL.md).
  • Sanitization: No automated sanitization is applied to the ingested diff data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:22 PM
Security Audit — agent-trust-hub — changes-review-loop