review-code

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands including git diff, git ls-files, and cat to identify and ingest file changes for the review process.
  • [COMMAND_EXECUTION]: Instructs the agent to execute a dynamic Python one-liner via python3 -c using the boto3 library to programmatically verify IAM service prefixes against official AWS service models.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted code changes from the local repository and passes them to other agents.
  • Ingestion points: Identifies and reads the full content of substantive changed files using git and cat in SKILL.md (Steps 1 and 2).
  • Boundary markers: Instructs the agent to wrap ingested code in Markdown fenced code blocks with descriptive labels to separate it from instructions in the subagent query.
  • Capability inventory: Access to local shell execution (git, cat, python3), file system reading, and the ability to invoke subagents or other skills like mass-remediate-pattern.
  • Sanitization: No explicit validation, filtering, or instruction-stripping of the code content is mentioned before it is interpolated into the prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:45 AM
Security Audit — agent-trust-hub — review-code