ln-52-delivery-reviewer

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests and processes untrusted data from repository files, code diffs, and tool outputs.
  • Ingestion points: The skill processes repository instructions, uncommitted work, implementation deltas, and external documentation as part of its review flow (SKILL.md Checklist 1, Tool Routing table).
  • Boundary markers: The skill employs a strict 'Execution contract' that requires deterministic evidence (e.g., compiler output, test results) rather than self-reported success, which serves as a logical boundary against untrusted instructions in processed files.
  • Capability inventory: The skill can execute repository-defined commands (build, lint, test) and utilize subagents in separate contexts (SKILL.md Tool Routing, Checklist 4.7).
  • Sanitization: The skill mitigates risks by enforcing a read-only execution environment and requiring that interpretations be grounded in observable outcomes and authoritative project policies.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 07:49 AM
Security Audit — agent-trust-hub — ln-52-delivery-reviewer