requesting-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The subagent template in
code-reviewer.mdinterpolates user-controlled data such as{DESCRIPTION}and{PLAN_REFERENCE}directly into its instructions. While this enables the code review functionality, it presents a surface where instructions embedded in project documentation or task descriptions could influence the subagent's behavior. - Ingestion points:
code-reviewer.md(placeholders for implementation details and requirements). - Boundary markers: Absent; data is placed directly under markdown headers.
- Capability inventory: Shell command execution via
git diffincode-reviewer.md. - Sanitization: Absent.
- [COMMAND_EXECUTION]: The skill executes
gitcommands (e.g.,git diff,git rev-parse,git log) to identify and analyze code changes between specific commits. These operations are performed locally within the repository and are consistent with the skill's stated purpose of facilitating code reviews.
Audit Metadata