acceptance-review

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external content such as issue descriptions and pull request bodies to build its "acceptance contract". This represents an indirect prompt injection surface where instructions embedded in external requirements could attempt to influence the agent's review logic.
  • Ingestion points: Authoritative issues and specifications (SKILL.md).
  • Boundary markers: No specific delimiters or warnings for embedded instructions are defined.
  • Capability inventory: File system read access and command execution (test runners) are implied in the verification steps.
  • Sanitization: No explicit sanitization or validation of external content is specified.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute commands to verify implementation behavior (e.g., "Run the smallest check that exercises each observable outcome"). This is a legitimate part of the code review and verification workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 08:05 AM
Security Audit — agent-trust-hub — acceptance-review