review-changes

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (git status, git log, git diff, git show) to gather context and inspect repository changes. While these are localized to the version control system, they represent a significant capability tier when combined with untrusted data processing.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) as it is designed to ingest and analyze untrusted data (code diffs, commit messages, and repository status) which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Content gathered via git diff, git log, and git show (SKILL.md, Step 2).
  • Boundary markers: Absent; the instructions do not provide delimiters or "ignore embedded instructions" warnings for the agent when processing diff content.
  • Capability inventory: Shell execution of Git commands.
  • Sanitization: None present; the skill treats the output of Git commands as authoritative context for its review process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — review-changes