code-reviewer
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The scripts
scripts/pr_analyzer.pyandscripts/review_report_generator.pyexecute shell commands viasubprocess.runto interact with Git and chain analysis tools. These operations are conducted using safe argument lists but involve external repository data and branch names which could be manipulated. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted code and diff data without adequate isolation or boundary instructions.
- Ingestion points:
scripts/pr_analyzer.pyreads git diff outputs andscripts/code_quality_checker.pyreads full source file contents into the agent's context. - Boundary markers: The skill does not employ delimiters or explicit instructions to prevent the model from interpreting processed content as commands or instructions.
- Capability inventory: File system read access and subprocess execution (
git). - Sanitization: No sanitization or filtering is applied to the analyzed code or diff content.
- [DATA_EXFILTRATION]: The tools provide a mechanism for the agent to read arbitrary local files based on path parameters. If an attacker successfully uses prompt injection to override the agent's constraints, they could potentially direct the quality checker to read and leak sensitive information from files outside the intended project scope (e.g., system configuration or credentials).
Audit Metadata