differential-review
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted input and maintains exploitable capabilities.
- Ingestion points: The skill ingests untrusted code and diff data via tools such as 'git diff' and 'gh pr view' as detailed in the methodology (skills/differential-review/methodology.md).
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the input as untrusted data or to ignore instructions embedded within the code being analyzed.
- Capability inventory: The skill utilizes 'Bash' for shell command execution and 'Write' for file system access, both of which are powerful tools that could be abused if the agent is tricked by malicious instructions in the code.
- Sanitization: The provided instructions do not include mechanisms to sanitize or filter the input data for malicious prompt segments hidden in comments or commit history.
Audit Metadata