review-ai-writing

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the codebase and git history, which acts as a potential injection vector. Ingestion points: Source code and markdown files found via find, git history through git log, and pull request metadata from gh pr view. Boundary markers: Absent; no delimiters are used to decouple scanned content from the agent's operating instructions. Capability inventory: Shell commands (git, find, gh, mkdir, python3), filesystem writes, and subagent management. Sanitization: Absent; untrusted data is ingested in raw form for LLM analysis.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands specifically git, find, and the GitHub CLI (gh) within SKILL.md. These tools are employed appropriately for the stated purpose of artifact discovery and retrieval for writing analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:17 AM
Security Audit — agent-trust-hub — review-ai-writing