code-review

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard version control commands (git status, git diff) to identify files for review. It also uses the omx tool to update state metadata during the review lifecycle.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted code from a repository, which presents a surface for indirect prompt injection attacks.
  • Ingestion points: Content from git diff is retrieved and directly embedded into the prompts for the code-reviewer and architect agents.
  • Boundary markers: The provided prompt templates for sub-agents lack clear delimiters or specific instructions to disregard embedded commands within the code scope.
  • Capability inventory: The skill has the ability to invoke sub-agents via the task() function and modify persistent state using omx.
  • Sanitization: There is no evidence of filtering or sanitization performed on the code content before it is processed by the AI agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — code-review