requesting-code-review

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for git operations, such as git rev-parse and git log, to determine commit ranges for review. It also directs the subagent to execute git diff commands.
  • [PROMPT_INJECTION]: The subagent template in code-reviewer.md incorporates external data via the {DESCRIPTION} and {PLAN_OR_REQUIREMENTS} placeholders. This creates a surface for indirect prompt injection if the task descriptions or project requirements contain malicious instructions designed to redirect the subagent's behavior.
  • Ingestion points: The {DESCRIPTION} and {PLAN_OR_REQUIREMENTS} variables in the code-reviewer.md template.
  • Boundary markers: The template does not utilize clear delimiters (like [BEGIN REQUIREMENTS]) or explicit instructions for the subagent to ignore commands embedded within the requirements text.
  • Capability inventory: The subagent is instructed to perform git diff and potentially access plan files via the provided paths.
  • Sanitization: There is no evidence of input validation or sanitization for the data interpolated into the subagent's prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — requesting-code-review