review-code
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local shell commands including
git diff,git ls-files, andcatto identify and ingest file changes for the review process. - [COMMAND_EXECUTION]: Instructs the agent to execute a dynamic Python one-liner via
python3 -cusing theboto3library to programmatically verify IAM service prefixes against official AWS service models. - [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted code changes from the local repository and passes them to other agents.
- Ingestion points: Identifies and reads the full content of substantive changed files using
gitandcatin SKILL.md (Steps 1 and 2). - Boundary markers: Instructs the agent to wrap ingested code in Markdown fenced code blocks with descriptive labels to separate it from instructions in the subagent query.
- Capability inventory: Access to local shell execution (
git,cat,python3), file system reading, and the ability to invoke subagents or other skills likemass-remediate-pattern. - Sanitization: No explicit validation, filtering, or instruction-stripping of the code content is mentioned before it is interpolated into the prompt.
Audit Metadata