peer-review-initiator
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
code-reviewer.mdfile defines shell command templates (git diff --stat {BASE_SHA}..{HEAD_SHA}) that interpolate variables into a command string. If an attacker can control the commit SHAs or branch names (e.g., by providing a malicious string likeHEAD; execute_malicious_code), it may lead to command injection when the subagent attempts to execute the diff. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data such as implementation descriptions and requirement documents, which can act as a vector for indirect instructions to the agent.
- Ingestion points: Untrusted content is interpolated into the
{WHAT_WAS_IMPLEMENTED},{PLAN_OR_REQUIREMENTS}, and{DESCRIPTION}placeholders incode-reviewer.md. - Boundary markers: There are no explicit delimiters or system instructions used to separate the review data from the agent's core instructions or to prevent the agent from following instructions embedded in the code/plans.
- Capability inventory: The subagent has the ability to execute shell commands (
git) and provide production-readiness assessments that could be biased by injected text. - Sanitization: The skill does not perform any validation or sanitization on the project data or git references before processing them.
Audit Metadata