review-local-changes

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from local files such as CLAUDE.md, README.md, and project source code to provide context for code review agents. This creates a potential surface for indirect prompt injection if those files contain malicious instructions meant to bias the AI's findings.
  • Ingestion points: Local repository files including CLAUDE.md, README.md, and modified source code (SKILL.md).
  • Boundary markers: None explicitly defined to distinguish between project data and review instructions.
  • Capability inventory: Execution of git commands (status, diff, blame) (SKILL.md).
  • Sanitization: None.
  • [COMMAND_EXECUTION]: The skill utilizes standard git commands (git status, git diff, git blame) to analyze changes and gather historical context. These operations are limited to the local repository and are appropriate for a code review tool.
  • [DATA_EXPOSURE]: The skill accesses local source code and version control metadata to perform its analysis. The data is processed within the agent's context for the purpose of the review, and no patterns indicating external data transmission or exfiltration were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:10 AM
Security Audit — agent-trust-hub — review-local-changes