effect-review-v4

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes several helper scripts (inspect-project.mjs, check-examples.mjs, setup.mjs) that invoke shell commands.
  • inspect-project.mjs uses git to inventory project files and diffs.
  • check-examples.mjs executes tsc (TypeScript compiler) and vitest (test runner) resolved from the local project's node_modules to verify that example code compiles and passes tests against the project's actual environment.
  • setup.mjs uses git to create isolated test fixtures.
  • These executions are part of the core functionality for code analysis and are performed using the local Node.js runtime without downloading external assets.
  • [INDIRECT_PROMPT_INJECTION]: As a code review tool, the skill naturally ingests untrusted content from the repository being analyzed. This represents a potential surface for indirect prompt injection if the analyzed code contains malicious instructions in comments or string literals.
  • The skill provides detailed 'Establish scope and ground truth' instructions and a specific delegation policy (defaulting to zero subagents) to help keep the agent focused and prevent unauthorized task expansion.
  • The instructions specifically advise the agent to remain read-only unless fixes are requested and to avoid self-auditing if asked to 'review' the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:25 AM
Security Audit — agent-trust-hub — effect-review-v4