code-review

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from pull request diffs, git history, and code comments. This content is passed directly to LLM agents (Sonnet and Haiku) to generate review feedback, creating a vulnerability surface where an attacker could influence the agent's output by embedding instructions in the PR code.
  • Ingestion points: Step 3 (gh pr view), Step 4 (git diff, git blame, and file reading), and Step 2 (CLAUDE.md discovery) in SKILL.md.
  • Boundary markers: The instructions do not define explicit delimiters or 'ignore' instructions for the sub-agents to distinguish between the code being reviewed and the analysis instructions.
  • Capability inventory: The skill uses the Bash tool to execute gh commands, enabling it to write comments back to GitHub pull requests based on the agent's findings.
  • Sanitization: There is no evidence of sanitization, escaping, or filtering of the pull request content before it is interpolated into the prompts for the review agents.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to perform legitimate development operations including git diff, git blame, grep, and gh (GitHub CLI) commands for viewing and commenting on pull requests. These actions are within the scope of a code review tool and utilize standard developer utilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:51 AM
Security Audit — agent-trust-hub — code-review