review
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from git diffs and local repository files like AGENTS.md. While it has file-write capabilities to apply fixes, the risk of malicious instructions within the diff influencing the agent is inherent to the review task and is mitigated by requiring explicit user approval for any changes.
- Ingestion points: git diff output, AGENTS.md, TODO.md, TODOS.md.
- Boundary markers: Absent.
- Capability inventory: Filesystem write.
- Sanitization: Absent.
- [COMMAND_EXECUTION]: The skill executes standard git commands such as git fetch and git diff to retrieve and compare source code changes. These commands are necessary for the skill's primary function of reviewing code updates.
Audit Metadata