review
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted code diffs and file contents, creating a surface for indirect prompt injection where malicious instructions inside the reviewed files could attempt to override the agent's behavior.
- Ingestion points: The skill reads repository history and file contents via
git log,git diff, and file reading tools in 'Step 0' and 'Step 1'. - Boundary markers: There are no explicit instructions or delimiters to isolate untrusted code content or warn the agent to ignore instructions embedded within the files it reviews.
- Capability inventory: The agent has access to powerful tools including
Bash,Write, andEdit, which could be abused if the agent's logic is subverted by malicious code content. - Sanitization: No validation or sanitization is performed on the data ingested from the repository before the agent processes it.
- [COMMAND_EXECUTION]: The skill provides the agent with shell command templates that interact with the filesystem and git repository.
- Evidence: The audit command in 'Step 0' (
git diff --name-only | xargs grep) does not use null-termination (-zfor git and-0for xargs), which is a common best-practice violation when handling potentially unusual filenames in a shell environment. - Evidence: In 'Step 6', the agent is instructed to create branches using a dynamically generated
<issue-slug>. If the agent is influenced by malicious content to generate a slug containing shell metacharacters, it could lead to unintended command execution during the branch creation process.
Audit Metadata