code-reviewer

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts scripts/pr_analyzer.py and scripts/review_report_generator.py execute shell commands via subprocess.run to interact with Git and chain analysis tools. These operations are conducted using safe argument lists but involve external repository data and branch names which could be manipulated.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted code and diff data without adequate isolation or boundary instructions.
  • Ingestion points: scripts/pr_analyzer.py reads git diff outputs and scripts/code_quality_checker.py reads full source file contents into the agent's context.
  • Boundary markers: The skill does not employ delimiters or explicit instructions to prevent the model from interpreting processed content as commands or instructions.
  • Capability inventory: File system read access and subprocess execution (git).
  • Sanitization: No sanitization or filtering is applied to the analyzed code or diff content.
  • [DATA_EXFILTRATION]: The tools provide a mechanism for the agent to read arbitrary local files based on path parameters. If an attacker successfully uses prompt injection to override the agent's constraints, they could potentially direct the quality checker to read and leak sensitive information from files outside the intended project scope (e.g., system configuration or credentials).
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — code-reviewer