audit-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves fetching information from external sources (Sentry issue searches and Firecrawl web searches) and incorporating that data into its reasoning process. This creates a vulnerability surface where maliciously crafted content in external logs or search results could attempt to influence the agent's code review conclusions.
- Ingestion points: Data ingested via
sentry:search_issuesandfirecrawl:firecrawl_searchJSON blocks. - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to treat external tool outputs as untrusted data.
- Capability inventory: The agent is authorized to use
gitcommands (log, diff, stat), search tools, and read local project files. - Sanitization: There are no instructions for sanitizing or escaping the content retrieved from external search tools before analysis.
Audit Metadata