review-panel
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from pull requests, creating an indirect prompt injection surface. \n
- Ingestion points: Pull request metadata, diffs, and epic/ticket descriptions are gathered from GitHub using standard tools and passed to specialized sub-agents for analysis.\n
- Boundary markers: reviewer personas are provided with clear instructions to treat PR descriptions and external claims as "claims, not evidence," prioritizing technical diff analysis and project documentation.\n
- Capability inventory: The orchestrator utilizes shell commands (gh, git) for data collection and executes project verification suites. reviewer personas are restricted to read-only tool access to prevent unauthorized modifications.\n
- Sanitization: Persona outputs are strictly validated against a JSON schema to ensure structural integrity and prevent malformed data from affecting the aggregation logic.\n- [COMMAND_EXECUTION]: The skill executes repository-specific verification commands defined in the project's documentation (e.g., CLAUDE.md) or epic tickets. This is a core functionality designed to ensure code quality and is mitigated by the use of isolated throwaway worktrees for all checkout and execution operations.
Audit Metadata