code-review
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill accepts user-supplied input for a "fixed point" (such as a branch name or commit SHA) and interpolates it directly into shell commands, including
git diff <fixed-point>...HEAD,git log <fixed-point>..HEAD, andgit rev-parse <fixed-point>. Although the skill includes a validation step usinggit rev-parse, there is a potential risk of command injection if the underlying shell environment does not properly sanitize the input. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external and potentially untrusted data that could contain malicious instructions meant to influence the analysis outcome.
- Ingestion points: The skill reads git commit messages (via
git log), the contents of the diff (viagit diff), and external specification files found indocs/,specs/, or.scratch/folders. - Boundary markers: The prompts provided to the sub-agents in Step 4 do not utilize explicit delimiters or instructions to ignore potential commands embedded within the diffs or specifications.
- Capability inventory: The skill's primary capabilities include reading local files and executing git read operations to generate a review report.
- Sanitization: There is no evidence of sanitization or filtering of the text content fetched from commit messages or spec files before it is passed into the agent's context.
Audit Metadata