review-llm-artifacts

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository during the review phase, creating a surface for indirect prompt injection.
  • Ingestion points: The skill reads file contents from the local repository during 'Step 3: Review the Four Categories' to detect code artifacts.
  • Boundary markers: The skill references a 'review-verification-protocol' and 'Anti-confabulation' rules to ground findings in source code, but does not explicitly define delimiters for the ingested code content within this file.
  • Capability inventory: The skill can execute shell commands (git, find, sed, grep), write to the local filesystem (creating the .beagle/ directory and JSON reports), and invoke subagents.
  • Sanitization: There is no explicit evidence of sanitization or escaping of the scanned file contents before they are processed by the agent or subagents.
  • [DYNAMIC_EXECUTION]: The skill uses Python scripts to perform internal data validation and integrity checks.
  • Evidence: 'Step 7: Verification' executes Python code via one-liners and heredocs to validate JSON structure and count consistency. This is a low-risk internal use of dynamic execution for validation purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — review-llm-artifacts