review

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted code diffs and file contents, creating a surface for indirect prompt injection where malicious instructions inside the reviewed files could attempt to override the agent's behavior.
  • Ingestion points: The skill reads repository history and file contents via git log, git diff, and file reading tools in 'Step 0' and 'Step 1'.
  • Boundary markers: There are no explicit instructions or delimiters to isolate untrusted code content or warn the agent to ignore instructions embedded within the files it reviews.
  • Capability inventory: The agent has access to powerful tools including Bash, Write, and Edit, which could be abused if the agent's logic is subverted by malicious code content.
  • Sanitization: No validation or sanitization is performed on the data ingested from the repository before the agent processes it.
  • [COMMAND_EXECUTION]: The skill provides the agent with shell command templates that interact with the filesystem and git repository.
  • Evidence: The audit command in 'Step 0' (git diff --name-only | xargs grep) does not use null-termination (-z for git and -0 for xargs), which is a common best-practice violation when handling potentially unusual filenames in a shell environment.
  • Evidence: In 'Step 6', the agent is instructed to create branches using a dynamically generated <issue-slug>. If the agent is influenced by malicious content to generate a slug containing shell metacharacters, it could lead to unintended command execution during the branch creation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — review