skills/google/adk-python/adk-review/Gen Agent Trust Hub

adk-review

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • Local Command Execution: The skill utilizes standard development tools, including git, pytest, and pre-commit, to retrieve code state and verify changes (SKILL.md, Workflow). These actions are scoped to the project environment and are typical for code review tasks.
  • Indirect Prompt Injection Surface: The skill ingests external data in the form of git diff output (SKILL.md, Workflow). This ingestion point represents a potential surface for instructions embedded within the reviewed code to influence the agent's behavior. The skill's capability inventory includes file writing and test execution (pytest), and while no specific boundary markers or sanitization are mentioned for the diff data, the instructions provide a strict checklist and report format to maintain task focus.
  • Execution of Local Tests: Verification of fixes involves running pytest (SKILL.md, Workflow), which executes code from the local repository. This is an inherent and expected capability for validating code correctness in a developer's local environment before changes are committed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 03:49 PM
Security Audit — agent-trust-hub — adk-review