workflow-review-changes-loop
Warn
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions to override platform-level behavior by telling the agent to ignore specific mode-switch instructions.
- [PROMPT_INJECTION]: Instructions explicitly direct the agent to hide the status and management of execution gates from the user, reducing transparency and user oversight.
- [COMMAND_EXECUTION]: Implements a recursive autonomous loop that re-invokes complex workflows up to 5 times based on repository state, which could lead to unintended continuous execution.
- [PROMPT_INJECTION]: The skill grants preemptive authorization for the agent to spawn sub-agents without seeking additional user approval for each instance, weakening the user-in-the-loop safety model.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository data from git diffs and file content, which serves as an ingestion point for instructions without defined sanitization or boundary markers.
Audit Metadata