code-review

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill accepts user-supplied input for a "fixed point" (such as a branch name or commit SHA) and interpolates it directly into shell commands, including git diff <fixed-point>...HEAD, git log <fixed-point>..HEAD, and git rev-parse <fixed-point>. Although the skill includes a validation step using git rev-parse, there is a potential risk of command injection if the underlying shell environment does not properly sanitize the input.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external and potentially untrusted data that could contain malicious instructions meant to influence the analysis outcome.
  • Ingestion points: The skill reads git commit messages (via git log), the contents of the diff (via git diff), and external specification files found in docs/, specs/, or .scratch/ folders.
  • Boundary markers: The prompts provided to the sub-agents in Step 4 do not utilize explicit delimiters or instructions to ignore potential commands embedded within the diffs or specifications.
  • Capability inventory: The skill's primary capabilities include reading local files and executing git read operations to generate a review report.
  • Sanitization: There is no evidence of sanitization or filtering of the text content fetched from commit messages or spec files before it is passed into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — code-review