review-delta

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes external source code and git diffs, which are untrusted data sources.
  • Ingestion points: The get_review_context_tool in SKILL.md is responsible for fetching external code snippets and diffs into the agent's context.
  • Boundary markers: There are no explicit instructions or delimiters defined to separate the ingested code content from the agent's review instructions.
  • Capability inventory: The skill invokes specialized tools for graph analysis (build_or_update_graph_tool, query_graph_tool, get_review_context_tool) but does not utilize general-purpose shell execution, file writing, or network request tools.
  • Sanitization: No sanitization, escaping, or validation mechanisms for the input code are specified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:37 PM