review
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data in the form of code diffs and reviewer feedback, which presents a surface for indirect prompt injection.\n
- Ingestion points: Code diffs and incoming human or machine feedback as described in the GIVING a review and RECEIVING a review sections of SKILL.md.\n
- Boundary markers: The skill instructions mention referencing external specifications and a constitution but do not provide explicit instructions for the agent to use delimiters when ingesting the code to be reviewed.\n
- Capability inventory: The agent has the ability to read project documentation, write to local wiki files (02-DOCS/wiki/sdd/decisions.md), and execute shell commands via npx.\n
- Sanitization: No explicit instructions for sanitizing or escaping the content of the diffs or comments are provided.\n- [COMMAND_EXECUTION]: The skill instructions include the use of npx to execute tools from the @ericrisco/rsc package for freezing, approving, and budgeting reviews (e.g., npx @ericrisco/rsc sello freeze). These represent vendor-owned resources.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes npx to fetch and execute the @ericrisco/rsc package from the npm registry. These resources originate from the skill author's infrastructure.
Audit Metadata