requesting-code-review
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for git operations, such as
git rev-parseandgit log, to determine commit ranges for review. It also directs the subagent to executegit diffcommands. - [PROMPT_INJECTION]: The subagent template in
code-reviewer.mdincorporates external data via the{DESCRIPTION}and{PLAN_OR_REQUIREMENTS}placeholders. This creates a surface for indirect prompt injection if the task descriptions or project requirements contain malicious instructions designed to redirect the subagent's behavior. - Ingestion points: The
{DESCRIPTION}and{PLAN_OR_REQUIREMENTS}variables in thecode-reviewer.mdtemplate. - Boundary markers: The template does not utilize clear delimiters (like
[BEGIN REQUIREMENTS]) or explicit instructions for the subagent to ignore commands embedded within the requirements text. - Capability inventory: The subagent is instructed to perform
git diffand potentially access plan files via the provided paths. - Sanitization: There is no evidence of input validation or sanitization for the data interpolated into the subagent's prompt.
Audit Metadata