review

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of code snippets or pull request diffs via the [SCOPE] and PR #123 inputs. This creates a vulnerability where instructions embedded within the code (e.g., hidden in comments) could attempt to manipulate the subagents' analysis or the final review verdict.
  • Ingestion points: Untrusted code is interpolated into subagent prompts via the [SCOPE] placeholder and PR diff fetching.
  • Boundary markers: The prompts provided to the critic, plan-reviewer, and review-agent do not utilize explicit delimiters or instructions to ignore embedded commands, increasing the risk of the agent obeying instructions found in the analyzed data.
  • Capability inventory: The skill is limited to text analysis and subagent orchestration; it does not demonstrate capabilities for writing files, executing shell commands, or establishing network connections.
  • Sanitization: No sanitization or escaping mechanisms are described to neutralize potential injection attacks within the processed code.
  • [SAFE]: The skill does not contain hardcoded credentials, obfuscated code, persistence mechanisms, or unauthorized remote code execution patterns. All defined behaviors are consistent with its stated purpose as a code review tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — review