githuman

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to run npx githuman, which downloads and executes the package from the official NPM registry. This is a standard and expected mechanism for utilizing Node.js CLI tools.
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands to manage the code review process, including starting the review server (npx githuman serve), managing todos, and performing Git operations (git add, git commit).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes AI-generated code changes which represent untrusted data, creating a potential surface for indirect prompt injection.
  • Ingestion points: The skill reads unstaged and staged files from the local repository to generate diffs for the GitHuman web interface (rules/review-workflow.md).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the reviewed code are documented.
  • Capability inventory: The skill facilitates shell command execution for Git operations and CLI management as described in rules/cli-commands.md.
  • Sanitization: No specific sanitization or validation of the ingested code changes is mentioned in the rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:17 PM
Security Audit — agent-trust-hub — githuman