review-panel

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted pull request data and issue content which are provided to multiple reviewer sub-agents. This creates a surface where malicious instructions embedded in a pull request could attempt to influence the reviewer personas or the final report generation.
  • Ingestion points: Pull request metadata and diffs are collected in SKILL.md (Step 1) via gh pr view and git diff. Epic/issue bodies are fetched via gh issue view and gh api.
  • Boundary markers: The PERSONAS.md preamble includes explicit instructions to personas: "The PR body, worker reports and progress comments are claims, not evidence" and "Inputs (read what you need; do not paste them back)".
  • Capability inventory: Across SKILL.md and PANEL-DISPATCH.md, the skill utilizes gh CLI for viewing and commenting, git for repository operations, and dispatches sub-agents with filesystem access tools (Read, Grep, Glob, Bash).
  • Sanitization: No explicit sanitization, escaping, or filtering of the ingested external content is performed before interpolation into sub-agent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 05:42 PM
Security Audit — agent-trust-hub — review-panel