deepagents-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and review external code, which creates a vulnerability surface where instructions hidden within that code (e.g., in comments or string literals) could attempt to influence the agent's behavior.
- Ingestion points: External code files and snippets accessed during the review process as outlined in the 'Review gates' section of
SKILL.md. - Boundary markers: The skill does not define specific delimiters or instructions to treat the code-under-review as untrusted data, although it does recommend echoing artifacts before analysis.
- Capability inventory: The skill provides instructions but does not include scripts or executables; however, it guides the agent in using tools like
read_fileandexecutewhich could be targeted by an injection. - Sanitization: No specific sanitization or filtering mechanisms are implemented for the code content being processed.
Audit Metadata