production-code-review
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to run local project tools, specifically typecheck and lint commands, provided they are fast and side-effect free. This involves executing scripts or binaries within the local environment based on the project's configuration.
- [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting untrusted data from external sources, including git diffs, pull request content via the
ghCLI, and local source files. A malicious actor could embed instructions within code comments or documentation to attempt to influence the agent's review output or behavior. - Ingestion points: The agent reads the working tree (
git diff), untracked files, branch comparisons, and GitHub PR diffs (gh pr diff). - Boundary markers: The instructions do not specify the use of delimiters or boundary markers when interpolating this untrusted code into the agent's context.
- Capability inventory: The agent has the capability to read files, execute git/gh commands, and run local linting/typechecking tools.
- Sanitization: There are no explicit instructions for sanitizing or escaping the content of the diffs or source files before processing.
Audit Metadata