wibaek-review-scan
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes untrusted data from the repository being reviewed and can trigger local tool execution. Ingestion points: Ingests the entire codebase, specific paths, and design documents including ADRs and RFCs (SKILL.md, design-doc-review.md). Boundary markers: No explicit boundary markers or 'ignore' instructions are defined to separate tool instructions from reviewed content. Capability inventory: The skill can execute various local tools such as build systems, tests, linters, and profilers to gather evidence (shared-hard-rules.md). Sanitization: There is no mention of sanitization or escaping of the ingested code or document content.
- [COMMAND_EXECUTION]: The skill utilizes local shell commands to run build tools, tests, and linters for the purpose of validating engineering risks and gathering technical evidence.
- [SAFE]: The skill's external references to other wibaek-review skills are consistent with its stated purpose and represent internal vendor resources from the skill author.
Audit Metadata