review

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted source code as its primary input, creating a surface for indirect prompt injection.
  • Ingestion points: Processes project files and user-specified paths within the instructions in SKILL.md.
  • Boundary markers: Uses <review_scope> tags to encapsulate input parameters.
  • Capability inventory: The skill possesses significant capabilities, including file system write access for report generation, the ability to modify source code through its 'auto-fix' feature, and the execution of local shell scripts.
  • Sanitization: No specific validation or sanitization of the input code content (such as comments or strings) is described before the data is processed by the review agents or used in consolidation logic.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:26 PM
Security Audit — agent-trust-hub — review