requesting-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary code from git diffs and interpolates it into the goals of subagents in
delegate_taskcalls (Step 5 and Step 7). This exposes the system to indirect prompt injection if the code being reviewed contains adversarial instructions targeted at the agent.\n - Ingestion points:
git diffoutput is inserted into the task goals of the 'Independent reviewer' and the 'Code fix agent' inSKILL.md.\n - Boundary markers: Step 5 includes an explicit instruction to treat input as data only, but Step 7 lacks established boundary markers or similar warnings for the fix agent.\n
- Capability inventory: The subagents are granted access to
terminalandfiletools, providing a path for execution or file modification if an injection is successful.\n - Sanitization: No sanitization or escaping is performed on the diff content before it is included in the subagent prompts.\n- [COMMAND_EXECUTION]: The skill executes various project-specific tools and scripts based on detected languages, such as
pytest,npm test,cargo test,go test,ruff,mypy, andeslint. These automated commands execute logic found within the project's local environment.
Audit Metadata