ln-52-delivery-reviewer
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests and processes untrusted data from repository files, code diffs, and tool outputs.
- Ingestion points: The skill processes repository instructions, uncommitted work, implementation deltas, and external documentation as part of its review flow (SKILL.md Checklist 1, Tool Routing table).
- Boundary markers: The skill employs a strict 'Execution contract' that requires deterministic evidence (e.g., compiler output, test results) rather than self-reported success, which serves as a logical boundary against untrusted instructions in processed files.
- Capability inventory: The skill can execute repository-defined commands (build, lint, test) and utilize subagents in separate contexts (SKILL.md Tool Routing, Checklist 4.7).
- Sanitization: The skill mitigates risks by enforcing a read-only execution environment and requiring that interpretations be grounded in observable outcomes and authoritative project policies.
Audit Metadata