workflow-review-changes-loop

Warn

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions to override platform-level behavior by telling the agent to ignore specific mode-switch instructions.
  • [PROMPT_INJECTION]: Instructions explicitly direct the agent to hide the status and management of execution gates from the user, reducing transparency and user oversight.
  • [COMMAND_EXECUTION]: Implements a recursive autonomous loop that re-invokes complex workflows up to 5 times based on repository state, which could lead to unintended continuous execution.
  • [PROMPT_INJECTION]: The skill grants preemptive authorization for the agent to spawn sub-agents without seeking additional user approval for each instance, weakening the user-in-the-loop safety model.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository data from git diffs and file content, which serves as an ingestion point for instructions without defined sanitization or boundary markers.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — workflow-review-changes-loop