review
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of code snippets or pull request diffs via the
[SCOPE]andPR #123inputs. This creates a vulnerability where instructions embedded within the code (e.g., hidden in comments) could attempt to manipulate the subagents' analysis or the final review verdict. - Ingestion points: Untrusted code is interpolated into subagent prompts via the
[SCOPE]placeholder and PR diff fetching. - Boundary markers: The prompts provided to the
critic,plan-reviewer, andreview-agentdo not utilize explicit delimiters or instructions to ignore embedded commands, increasing the risk of the agent obeying instructions found in the analyzed data. - Capability inventory: The skill is limited to text analysis and subagent orchestration; it does not demonstrate capabilities for writing files, executing shell commands, or establishing network connections.
- Sanitization: No sanitization or escaping mechanisms are described to neutralize potential injection attacks within the processed code.
- [SAFE]: The skill does not contain hardcoded credentials, obfuscated code, persistence mechanisms, or unauthorized remote code execution patterns. All defined behaviors are consistent with its stated purpose as a code review tool.
Audit Metadata