review-assurance-case
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes external CLI tools (GitHub Copilot, Claude, Codex, and Gemini) using
asyncio.create_subprocess_exec. For the GitHub provider, it explicitly passes the--allow-all-toolsand--allow-all-pathsflags. The Google provider is configured with the--yoloflag. These settings grant the external agent unrestricted access to system tools and the filesystem, which poses a significant risk if the agent is compromised or tricked via injection. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted markdown and JSON content from user-specified files and interpolates it directly into LLM prompts in
prompts.py. The templates lack sufficient isolation, such as delimiters or clear instructions to ignore embedded commands, allowing malicious content in the reviewed reports to potentially hijack the session and utilize the broad capabilities granted by the CLI flags. - [DATA_EXFILTRATION]: The
memory_integration.pyscript automatically sends snippets of review findings to aMemoryClient. This mechanism could lead to the unintended exfiltration and persistence of sensitive data or secrets if they are present in the files being reviewed. - [REMOTE_CODE_EXECUTION]: The skill uses
importlib.utilto dynamically load and execute a Python module from thetaxonomy/subdirectory at runtime. This dynamic loading of code from relative paths is a risky pattern that could be exploited for local code execution if the directory is writable. - [DATA_EXFILTRATION]: The skill modifies the Python system path in
config.pyandmemory_integration.pyto include parent directories, which can facilitate path hijacking or unintended module imports in shared environments.
Audit Metadata