effect-review-v4
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several helper scripts (
inspect-project.mjs,check-examples.mjs,setup.mjs) that invoke shell commands. inspect-project.mjsusesgitto inventory project files and diffs.check-examples.mjsexecutestsc(TypeScript compiler) andvitest(test runner) resolved from the local project'snode_modulesto verify that example code compiles and passes tests against the project's actual environment.setup.mjsusesgitto create isolated test fixtures.- These executions are part of the core functionality for code analysis and are performed using the local Node.js runtime without downloading external assets.
- [INDIRECT_PROMPT_INJECTION]: As a code review tool, the skill naturally ingests untrusted content from the repository being analyzed. This represents a potential surface for indirect prompt injection if the analyzed code contains malicious instructions in comments or string literals.
- The skill provides detailed 'Establish scope and ground truth' instructions and a specific delegation policy (defaulting to zero subagents) to help keep the agent focused and prevent unauthorized task expansion.
- The instructions specifically advise the agent to remain read-only unless fixes are requested and to avoid self-auditing if asked to 'review' the skill itself.
Audit Metadata