review-ai-writing
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the codebase and git history, which acts as a potential injection vector. Ingestion points: Source code and markdown files found via
find, git history throughgit log, and pull request metadata fromgh pr view. Boundary markers: Absent; no delimiters are used to decouple scanned content from the agent's operating instructions. Capability inventory: Shell commands (git,find,gh,mkdir,python3), filesystem writes, and subagent management. Sanitization: Absent; untrusted data is ingested in raw form for LLM analysis. - [COMMAND_EXECUTION]: The skill utilizes shell commands specifically
git,find, and the GitHub CLI (gh) withinSKILL.md. These tools are employed appropriately for the stated purpose of artifact discovery and retrieval for writing analysis.
Audit Metadata