requesting-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs a subagent to process external data, creating a surface for indirect prompt injection.
- Ingestion points: The [DESCRIPTION] and [PLAN_OR_REQUIREMENTS] placeholders in code-reviewer.md, along with the source code retrieved via git diff and git show.
- Boundary markers: The prompt template uses Markdown section headers to separate instructions from user-provided content.
- Capability inventory: The reviewer subagent has the ability to execute git commands and perform file system operations such as git worktree add.
- Sanitization: No specific sanitization or filtering logic is present to prevent embedded instructions within the code or plans from influencing the subagent's behavior.
Audit Metadata