review-code

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the subprocess module and asyncio.create_subprocess_exec to interact with external tools including git (for repository context), docker (for containerized reviews), xclip (for clipboard operations), and various AI provider CLIs (gh, claude, codex, gemini). These calls are implemented using list-based arguments which correctly mitigates standard shell injection risks.
  • [DATA_EXFILTRATION]: The skill's primary function involves reading local project files and git diffs to generate review bundles. These bundles are then passed to external AI providers or a local proxy (localhost:4001). This behavior is intended for the purpose of code review and is limited to the files explicitly selected or detected within the repository.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data (the code to be reviewed) and architectural context, which are then interpolated into prompts for LLM reviewers. The skill uses Markdown code blocks as boundary markers to mitigate accidental obedience to instructions contained within the code. The reviewer's output is explicitly described as advisory, requiring agent or human integration.
  • [EXTERNAL_DOWNLOADS]: The skill calls CLIs that communicate with official AI provider APIs. These interactions target well-known services and are consistent with the skill's stated multi-provider support.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — review-code