review-tui
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes standard local development tools such as git, grep, and the Go toolchain (go build, go vet, and go test) to analyze and verify source code. These operations are restricted to the local environment and are typical for the skill's stated purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill has an inherent attack surface for indirect prompt injection as it processes and executes tests on external, potentially untrusted source code. * Ingestion points: The skill reads Go source files identified via git and grep commands in the initial steps. * Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions that might be embedded within the source files or test data. * Capability inventory: The 'Post-Fix Verification' section utilizes go build and go test, which compile and execute code from the project under review. * Sanitization: There is no evidence of input validation or sanitization applied to the source code before analysis or execution.
Audit Metadata