code-review
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user code as its primary input without explicit boundary markers or sanitization, creating a surface for indirect prompt injection. Malicious instructions embedded in comments or strings within the code being reviewed could potentially influence the agent's output or behavior. (Ingestion point: User-provided code snippets and pull request content; Boundary markers: Absent; Capability inventory: Execute tests and lints; Sanitization: Absent).
- [COMMAND_EXECUTION]: The skill explicitly directs the agent to execute local tests and lints found in the codebase being reviewed. This provides a mechanism for executing arbitrary commands if the target repository contains malicious build or test scripts (e.g., in a Makefile or package.json). Evidence: 'If you can run tests/lints locally, do it and report the commands/outcome.' (SKILL.md).
- [COMMAND_EXECUTION]: The skill uses the
rg(ripgrep) command-line tool to search its internal reference documents. While these commands are hardcoded to search its own files, they represent an active use of shell-level command execution. Evidence: Multiple instances ofrg -ncalls in SKILL.md.
Audit Metadata