skills/shipshitdev/skills/qa-reviewer/Gen Agent Trust Hub

qa-reviewer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading and analyzing arbitrary files within a project repository to verify requirements and detect bugs. This creates a surface for indirect prompt injection where malicious instructions embedded in source code or project documentation could influence the agent's QA assessment.
  • Ingestion points: The agent is instructed to read various project files, including project configuration files like AGENTS.md and CLAUDE.md, and any files modified during the task (SKILL.md, references/full-guide.md).
  • Boundary markers: No boundary markers or 'ignore' instructions are provided to distinguish between the content of the files and the agent's instructions.
  • Capability inventory: The skill uses shell commands (ls, grep, find, git) and local script execution (python3) to audit work (SKILL.md, references/full-guide.md).
  • Sanitization: There is no evidence of content sanitization or filtering before the agent processes the file data.
  • [DYNAMIC_EXECUTION]: The skill recommends using a Python one-liner to verify syntax, specifically to ensure markdown code blocks are balanced. While the script itself is benign, it represents the dynamic generation and execution of code based on local file content.
  • Evidence: The references/full-guide.md file contains a command pattern using python3 -c to read a file and count backtick occurrences.
  • [COMMAND_EXECUTION]: The skill uses various shell commands to inspect the file system and project state.
  • Evidence: Commands such as ls -la, grep, find, and git diff are used throughout SKILL.md and references/full-guide.md to verify file existence, verify directory structures, and audit changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — qa-reviewer