review-delta
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes external source code and git diffs, which are untrusted data sources.
- Ingestion points: The
get_review_context_toolinSKILL.mdis responsible for fetching external code snippets and diffs into the agent's context. - Boundary markers: There are no explicit instructions or delimiters defined to separate the ingested code content from the agent's review instructions.
- Capability inventory: The skill invokes specialized tools for graph analysis (
build_or_update_graph_tool,query_graph_tool,get_review_context_tool) but does not utilize general-purpose shell execution, file writing, or network request tools. - Sanitization: No sanitization, escaping, or validation mechanisms for the input code are specified in the instructions.
Audit Metadata