requesting-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary code from git diffs and interpolates it into the goals of subagents in delegate_task calls (Step 5 and Step 7). This exposes the system to indirect prompt injection if the code being reviewed contains adversarial instructions targeted at the agent.\n
  • Ingestion points: git diff output is inserted into the task goals of the 'Independent reviewer' and the 'Code fix agent' in SKILL.md.\n
  • Boundary markers: Step 5 includes an explicit instruction to treat input as data only, but Step 7 lacks established boundary markers or similar warnings for the fix agent.\n
  • Capability inventory: The subagents are granted access to terminal and file tools, providing a path for execution or file modification if an injection is successful.\n
  • Sanitization: No sanitization or escaping is performed on the diff content before it is included in the subagent prompts.\n- [COMMAND_EXECUTION]: The skill executes various project-specific tools and scripts based on detected languages, such as pytest, npm test, cargo test, go test, ruff, mypy, and eslint. These automated commands execute logic found within the project's local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:35 PM