review-panel
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8). It ingests untrusted data from the local repository and passes it to LLM reviewers without explicit boundary markers to isolate instructions from data.
- Ingestion points: Reads files from the filesystem via
git diff --name-onlyandgit ls-filesin Phase 1. - Boundary markers: No specific delimiters or 'ignore embedded instructions' warnings are applied to the file contents passed to
consult-llmin Phase 2. - Capability inventory: The skill has
Edit,Write, andBashcapabilities, including the power to commit code changes in Phase 5. - Sanitization: No sanitization or filtering of the repository file content is performed before interpolation into the review task.
- [COMMAND_EXECUTION]: The skill uses the dynamic context injection syntax (
!consult-llm models) to list available reviewers at load time. While this is a benign use of project-specific tooling, it represents a pre-execution command invocation. - [COMMAND_EXECUTION]: When the
--fixflag is enabled, the agent can automatically modify files and performgit commitoperations. Although the skill categorizes fixes into 'Obvious' (automatic) and 'Quick judgment call' (interactive), a compromised or injected reviewer could potentially trick the agent into applying malicious code changes or backdoors under the guise of an 'obvious' fix.
Audit Metadata