guided-flow-review

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill identifies and executes repository-defined commands, such as formatters, linters, and test suites, during the fix verification process described in references/fix-execution.md.- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from pull requests and repository files which can contain instructions intended to influence the agent. • Ingestion points: Pull request metadata and diffs via gh pr view and git diff, as well as repository-wide instruction files and source code. • Boundary markers: Instructions explicitly tell the agent to treat added or modified instruction files as code under review rather than instructions to be followed. • Capability inventory: Access to the Bash tool for executing git, gh, and repository-specific verification scripts. • Sanitization: The skill relies on role-based behavioral instructions for the agent rather than programmatic filtering of ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:15 PM
Security Audit — agent-trust-hub — guided-flow-review