review-python

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill relies on standard local development tools for its operations. All shell commands are used for legitimate project analysis purposes without signs of malicious intent or unauthorized access.
  • [COMMAND_EXECUTION]: The skill executes local commands such as git diff, grep, ruff, mypy, and pytest. These are standard tools for identifying changed files, searching for patterns, linting, and testing within a development environment. No injection of unvalidated user input into these commands was detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an inherent ingestion surface because its primary function is to process and review external source code. While malicious code could theoretically contain instructions to subvert the reviewer, the skill's narrow focus and lack of high-risk capabilities (like external network access or credential reading) mitigate this risk.
  • Ingestion points: Files identified via git diff and content searched via grep in SKILL.md.
  • Boundary markers: The skill does not explicitly use boundary markers for the code it reads, but it follows a structured 'Hard Gates' sequence to verify findings.
  • Capability inventory: Limited to local code analysis tools (git, grep, ruff, mypy, pytest).
  • Sanitization: None detected for the ingested file contents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — review-python