code-review
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external code content and git diffs, which serve as untrusted ingestion points. A malicious actor could embed instructions within code comments or logic that might influence the agent's behavior during the review process.
- Ingestion points: Untrusted data enters the agent context through the files and git diff output processed by the agent in SKILL.md.
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the code content as data only and ignore any embedded instructions.
- Capability inventory: The skill environment allows the use of Read, Grep, Glob, and Bash tools, representing a high-capability surface if an injection occurs.
- Sanitization: The skill does not include any specific mechanisms for filtering, validating, or sanitizing the input data from the codebase being reviewed.
Audit Metadata