revolver-review

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a workflow that processes untrusted external data (the code changes being reviewed), creating a surface for indirect prompt injection.
  • Ingestion points: The target code changes and documentation being analyzed by the orchestrator (SKILL.md).
  • Boundary markers: The instructions do not specify the use of clear delimiters or warnings to ignore instructions within the target code to separate it from the agent's logic.
  • Capability inventory: The process involves file reading via 'grep', file writing to apply fixes, and potential command execution when 're-running' checks or tests (SKILL.md).
  • Sanitization: There is no instruction to validate or sanitize the target content before it is processed by the sub-agents or the orchestrator.
  • [COMMAND_EXECUTION]: Reviewer sub-agents are instructed to 're-run / reconcile the evidence yourself' (SKILL.md), which involves executing code or test harnesses from the target project. This execution path is inherently risky if the target project code is malicious or includes adversarial test cases.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 04:00 PM
Security Audit — agent-trust-hub — revolver-review