code-review
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
skill-gate --strictcommand at the repository root. This is intended to run automated checks such as formatting, linting, and security scans (SCA/SAST). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, specifically source code, diffs, and PR descriptions, which could contain adversarial content intended to override agent instructions.
- Ingestion points: User-provided code, diffs, PRs, and design documents specified in the instructions.
- Boundary markers: The skill does not define explicit delimiters or instructions to treat the ingested code as untrusted data.
- Capability inventory: The agent has the capability to execute shell commands (
skill-gate) and read files throughout the repository. - Sanitization: No input validation or sanitization steps are defined before the agent analyzes the provided code changes.
Audit Metadata