Adversarial review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to interact with source control CLIs (
gh,glab) andgiton a shared computer to read repository history and diffs. While standard for developer tools, it involves executing local commands based on branch and base parameters provided in the task context. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest and analyze external code changes from branches, it has a surface for indirect prompt injection. Maliciously crafted code or commit messages in the analyzed branch could attempt to influence the subagent's behavior, though the structured JSON output format and 'assume-malicious' task framing provide some mitigation.
Audit Metadata