code-review
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from the repository that could contain malicious instructions designed to manipulate the sub-agents' review output.
- Ingestion points: Git diffs, commit logs, and specification files located in
docs/,specs/, or.scratch/(SKILL.md). - Boundary markers: The instructions in Step 4 ("Spawn both sub-agents in parallel") do not specify the use of delimiters or "ignore embedded instructions" warnings when interpolating the diff and spec contents into sub-agent prompts.
- Capability inventory: The skill uses the
Agenttool to executegeneral-purposesub-agents which process the untrusted data. - Sanitization: There is no evidence of sanitization or escaping of the diff or specification content before it is passed to the sub-agents.
Audit Metadata