subagent-review

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository, creating a surface for potential indirect prompt injection.
  • Ingestion points: Git logs, diffs, and source code files are read as context for subagents during the review process (Steps 1 and 3).
  • Boundary markers: No explicit structural delimiters or specific "ignore embedded instructions" warnings are provided when passing repository data to the subagents.
  • Capability inventory: The skill utilizes file system read capabilities and the ability to spawn subagent tasks.
  • Sanitization: The skill implements a mandatory verification phase (Step 4) where the parent agent must manually reproduce each finding against the code and discard any unverified claims.
  • [COMMAND_EXECUTION]: The skill utilizes local Git commands to identify commit ranges and analyze the repository state.
  • Evidence: Commands include git fetch origin, git merge-base origin/main HEAD, git log --oneline, and git diff --stat described in the 'Process' section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 02:00 AM
Security Audit — agent-trust-hub — subagent-review