skills/openai/codex/review-agent/Gen Agent Trust Hub

review-agent

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [Potential Surface for Indirect Prompt Injection]: The agent is instructed to read and analyze external code changes and documentation (such as AGENTS.md). Content within these sources could potentially contain instructions intended to influence the agent's behavior or findings.
  • Ingestion points: Code changes, diffs, and the AGENTS.md file are read as specified in SKILL.md.
  • Boundary markers: No specific delimiters or boundary markers are defined to separate the code content from the agent's primary instructions.
  • Capability inventory: The skill involves executing local git commands (git merge-base, git diff) in SKILL.md to perform version comparison.
  • Sanitization: No specific sanitization or filtering of the code content is mentioned prior to analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 09:12 PM
Security Audit — agent-trust-hub — review-agent