code-review

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill reads untrusted project files such as 'agents.md', 'todo.md', and the codebase itself to perform reviews. These files could contain malicious instructions designed to hijack the agent's behavior.
  • Ingestion points: 'agents.md', 'todo.md', and project source files.
  • Boundary markers: Absent. No instructions are provided to delimit or ignore instructions within the analyzed data.
  • Capability inventory: File system read and file system write.
  • Sanitization: Absent.
  • [COMMAND_EXECUTION]: Automated File System Write. The skill instructs the agent to 'Always save the report as markdown file in the application root' for every review, which is an automated side effect that occurs without explicit per-request user confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 08:14 PM
Security Audit — agent-trust-hub — code-review