githuman
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to run
npx githuman, which downloads and executes the package from the official NPM registry. This is a standard and expected mechanism for utilizing Node.js CLI tools. - [COMMAND_EXECUTION]: The skill relies on executing shell commands to manage the code review process, including starting the review server (
npx githuman serve), managing todos, and performing Git operations (git add,git commit). - [INDIRECT_PROMPT_INJECTION]: The skill processes AI-generated code changes which represent untrusted data, creating a potential surface for indirect prompt injection.
- Ingestion points: The skill reads unstaged and staged files from the local repository to generate diffs for the GitHuman web interface (
rules/review-workflow.md). - Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the reviewed code are documented.
- Capability inventory: The skill facilitates shell command execution for Git operations and CLI management as described in
rules/cli-commands.md. - Sanitization: No specific sanitization or validation of the ingested code changes is mentioned in the rules.
Audit Metadata