light-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of instructions for performing code reviews and contains no malicious code or suspicious activity.\n- [PROMPT_INJECTION]: The skill possesses an inherent attack surface for indirect prompt injection because its primary function involves analyzing untrusted code changes. A malicious diff could potentially include instructions that attempt to manipulate the agent's logic.\n
  • Ingestion points: The skill reads code diffs using the git diff command.\n
  • Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded in the analyzed code.\n
  • Capability inventory: The agent uses standard tools including Read, Bash, Grep, and Glob.\n
  • Sanitization: The skill does not perform specific sanitization of the analyzed diff data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 11:53 AM
Security Audit — agent-trust-hub — light-reviewer