subagent-review
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository, creating a surface for potential indirect prompt injection.
- Ingestion points: Git logs, diffs, and source code files are read as context for subagents during the review process (Steps 1 and 3).
- Boundary markers: No explicit structural delimiters or specific "ignore embedded instructions" warnings are provided when passing repository data to the subagents.
- Capability inventory: The skill utilizes file system read capabilities and the ability to spawn subagent tasks.
- Sanitization: The skill implements a mandatory verification phase (Step 4) where the parent agent must manually reproduce each finding against the code and discard any unverified claims.
- [COMMAND_EXECUTION]: The skill utilizes local Git commands to identify commit ranges and analyze the repository state.
- Evidence: Commands include
git fetch origin,git merge-base origin/main HEAD,git log --oneline, andgit diff --statdescribed in the 'Process' section of SKILL.md.
Audit Metadata