production-code-review

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to run local project tools, specifically typecheck and lint commands, provided they are fast and side-effect free. This involves executing scripts or binaries within the local environment based on the project's configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting untrusted data from external sources, including git diffs, pull request content via the gh CLI, and local source files. A malicious actor could embed instructions within code comments or documentation to attempt to influence the agent's review output or behavior.
  • Ingestion points: The agent reads the working tree (git diff), untracked files, branch comparisons, and GitHub PR diffs (gh pr diff).
  • Boundary markers: The instructions do not specify the use of delimiters or boundary markers when interpolating this untrusted code into the agent's context.
  • Capability inventory: The agent has the capability to read files, execute git/gh commands, and run local linting/typechecking tools.
  • Sanitization: There are no explicit instructions for sanitizing or escaping the content of the diffs or source files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 09:16 AM
Security Audit — agent-trust-hub — production-code-review