effect-review
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted source code via git diff results and passes the content to various specialized reviewer agents, creating a potential vector where instructions within the analyzed code could attempt to manipulate the review output. -- Ingestion points: Files detected by
git diffinSKILL.md(Step 1) and processed in Step 3. -- Boundary markers: The prompt provided to sub-agents lacks strong delimiters or specific 'ignore embedded instructions' directives to isolate the untrusted code content. -- Capability inventory: The skill utilizes theAgenttool to perform multi-role analysis and generate unified reports based on filesystem content. -- Sanitization: No validation, escaping, or filtering of the code content is performed before analysis.
Audit Metadata