executar-review

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs shell operations including git status, git diff, git log, bun run test, and bun run typecheck. These are used to examine code changes and verify build integrity.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted documentation and code diffs. 1. Ingestion points: Files at ./tasks/prd-[feature-slug]/techspec.md, ./tasks/prd-[feature-slug]/tasks.md, and git diff output. 2. Boundary markers: None. There are no instructions to ignore embedded commands in the analyzed content. 3. Capability inventory: Subprocess execution via git and bun, file system read access. 4. Sanitization: None. Data is processed as raw text for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 03:23 AM
Security Audit — agent-trust-hub — executar-review