review-local-changes
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from local files such as
CLAUDE.md,README.md, and project source code to provide context for code review agents. This creates a potential surface for indirect prompt injection if those files contain malicious instructions meant to bias the AI's findings. - Ingestion points: Local repository files including
CLAUDE.md,README.md, and modified source code (SKILL.md). - Boundary markers: None explicitly defined to distinguish between project data and review instructions.
- Capability inventory: Execution of
gitcommands (status, diff, blame) (SKILL.md). - Sanitization: None.
- [COMMAND_EXECUTION]: The skill utilizes standard
gitcommands (git status,git diff,git blame) to analyze changes and gather historical context. These operations are limited to the local repository and are appropriate for a code review tool. - [DATA_EXPOSURE]: The skill accesses local source code and version control metadata to perform its analysis. The data is processed within the agent's context for the purpose of the review, and no patterns indicating external data transmission or exfiltration were detected.
Audit Metadata