skills/raine/consult-llm/review-panel/Gen Agent Trust Hub

review-panel

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8). It ingests untrusted data from the local repository and passes it to LLM reviewers without explicit boundary markers to isolate instructions from data.
  • Ingestion points: Reads files from the filesystem via git diff --name-only and git ls-files in Phase 1.
  • Boundary markers: No specific delimiters or 'ignore embedded instructions' warnings are applied to the file contents passed to consult-llm in Phase 2.
  • Capability inventory: The skill has Edit, Write, and Bash capabilities, including the power to commit code changes in Phase 5.
  • Sanitization: No sanitization or filtering of the repository file content is performed before interpolation into the review task.
  • [COMMAND_EXECUTION]: The skill uses the dynamic context injection syntax (!consult-llm models) to list available reviewers at load time. While this is a benign use of project-specific tooling, it represents a pre-execution command invocation.
  • [COMMAND_EXECUTION]: When the --fix flag is enabled, the agent can automatically modify files and perform git commit operations. Although the skill categorizes fixes into 'Obvious' (automatic) and 'Quick judgment call' (interactive), a compromised or injected reviewer could potentially trick the agent into applying malicious code changes or backdoors under the guise of an 'obvious' fix.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 02:19 PM
Security Audit — agent-trust-hub — review-panel