quick-review

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill performs its operations using standard local git commands and file system access. No remote code execution or data exfiltration attempts were detected.
  • [PROMPT_INJECTION]: The skill processes untrusted code content from the repository, creating a surface for indirect prompt injection. Malicious instructions within the code being reviewed could potentially attempt to manipulate the agent's review findings or influence the descriptive filename used for the output report. 1. Ingestion points: SKILL.md (Step 1: Gather Changes reads diffs and files). 2. Boundary markers: Absent. 3. Capability inventory: Local file read/write and shell command execution via git. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — quick-review