review-frontend
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data (frontend source code) which presents an attack surface for instructions embedded within comments or strings in the code being reviewed.
- Ingestion points: The skill reads file paths and content in Step 1 (git diff), Step 2 (grep detection), and Step 6 (manual code re-reading).
- Boundary markers: The instructions do not provide explicit delimiters or "ignore instructions" warnings for the agent to use when processing the code files.
- Capability inventory: The agent is authorized to execute shell commands (git, grep) and run project scripts (npm run lint/test/typecheck) which could be influenced by injected instructions.
- Sanitization: There is no evidence of sanitization or filtering for embedded prompt instructions in the files being reviewed.
Audit Metadata