requesting-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The subagent template in code-reviewer.md interpolates user-controlled data such as {DESCRIPTION} and {PLAN_REFERENCE} directly into its instructions. While this enables the code review functionality, it presents a surface where instructions embedded in project documentation or task descriptions could influence the subagent's behavior.
  • Ingestion points: code-reviewer.md (placeholders for implementation details and requirements).
  • Boundary markers: Absent; data is placed directly under markdown headers.
  • Capability inventory: Shell command execution via git diff in code-reviewer.md.
  • Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill executes git commands (e.g., git diff, git rev-parse, git log) to identify and analyze code changes between specific commits. These operations are performed locally within the repository and are consistent with the skill's stated purpose of facilitating code reviews.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — requesting-code-review