peer-review-initiator

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The code-reviewer.md file defines shell command templates (git diff --stat {BASE_SHA}..{HEAD_SHA}) that interpolate variables into a command string. If an attacker can control the commit SHAs or branch names (e.g., by providing a malicious string like HEAD; execute_malicious_code), it may lead to command injection when the subagent attempts to execute the diff.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data such as implementation descriptions and requirement documents, which can act as a vector for indirect instructions to the agent.
  • Ingestion points: Untrusted content is interpolated into the {WHAT_WAS_IMPLEMENTED}, {PLAN_OR_REQUIREMENTS}, and {DESCRIPTION} placeholders in code-reviewer.md.
  • Boundary markers: There are no explicit delimiters or system instructions used to separate the review data from the agent's core instructions or to prevent the agent from following instructions embedded in the code/plans.
  • Capability inventory: The subagent has the ability to execute shell commands (git) and provide production-readiness assessments that could be biased by injected text.
  • Sanitization: The skill does not perform any validation or sanitization on the project data or git references before processing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — peer-review-initiator