review-changes
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (
git status,git log,git diff,git show) to gather context and inspect repository changes. While these are localized to the version control system, they represent a significant capability tier when combined with untrusted data processing. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) as it is designed to ingest and analyze untrusted data (code diffs, commit messages, and repository status) which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Content gathered via
git diff,git log, andgit show(SKILL.md, Step 2). - Boundary markers: Absent; the instructions do not provide delimiters or "ignore embedded instructions" warnings for the agent when processing diff content.
- Capability inventory: Shell execution of Git commands.
- Sanitization: None present; the skill treats the output of Git commands as authoritative context for its review process.
Audit Metadata