code-review

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user code as its primary input without explicit boundary markers or sanitization, creating a surface for indirect prompt injection. Malicious instructions embedded in comments or strings within the code being reviewed could potentially influence the agent's output or behavior. (Ingestion point: User-provided code snippets and pull request content; Boundary markers: Absent; Capability inventory: Execute tests and lints; Sanitization: Absent).
  • [COMMAND_EXECUTION]: The skill explicitly directs the agent to execute local tests and lints found in the codebase being reviewed. This provides a mechanism for executing arbitrary commands if the target repository contains malicious build or test scripts (e.g., in a Makefile or package.json). Evidence: 'If you can run tests/lints locally, do it and report the commands/outcome.' (SKILL.md).
  • [COMMAND_EXECUTION]: The skill uses the rg (ripgrep) command-line tool to search its internal reference documents. While these commands are hardcoded to search its own files, they represent an active use of shell-level command execution. Evidence: Multiple instances of rg -n calls in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 11:54 AM
Security Audit — agent-trust-hub — code-review