review-prompt

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script review_prompt.py executes commands defined in the --validator and --smoke CLI flags using subprocess.run(shell=True) in the _run_configured_commands function. This is a core feature for verifying prompt performance but allows for arbitrary command execution based on CLI input.
  • [CREDENTIALS_UNSAFE]: The variable SCILLM_KEY in review_prompt.py has a hardcoded default value of sk-dev-proxy-123. While likely a dummy value for development, hardcoding credentials remains a security risk.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted template and source data, allows an LLM to modify that data, and subsequently executes commands. 1. Ingestion points: Untrusted data enters the context through the --template, --source, and --payload flags in review_prompt.py. 2. Boundary markers: The script uses triple backticks to delimit content in model requests, providing basic isolation. 3. Capability inventory: The skill performs file writes to the template path and executes shell commands via the _run_configured_commands function. 4. Sanitization: The script strips markdown formatting fences from LLM fixes before writing them to disk, but does not further validate the content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — review-prompt