clean-code-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard git CLI commands (git status, git diff, git symbolic-ref, git merge-base, git diff --name-only, git diff --diff-filter=AR) to identify the review target, determine the base branch, and extract the list of changed files. This is legitimate behavior for a tool designed to review code changes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (git diffs and codebase content), which serves as an ingestion point for potential indirect prompt injection.
  • Ingestion points: Git diff output and source code files classified during the inspection phase (e.g., .ts, .py, .tsx, .css).
  • Boundary markers: The instructions provide a highly structured output format (Style, Correctness, Verdict sections) and specific finding templates, which help constrain the agent's output behavior.
  • Capability inventory: Reading sibling skill files (e.g., ../clean-typescript/SKILL.md), reading repository files, and executing git commands.
  • Sanitization: The instructions do not define specific sanitization or escaping mechanisms for the untrusted content being reviewed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:59 PM
Security Audit — agent-trust-hub — clean-code-reviewer