code-review
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes standard version control commands (
git status,git diff) to identify files for review. It also uses theomxtool to update state metadata during the review lifecycle. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted code from a repository, which presents a surface for indirect prompt injection attacks.
- Ingestion points: Content from
git diffis retrieved and directly embedded into the prompts for thecode-reviewerandarchitectagents. - Boundary markers: The provided prompt templates for sub-agents lack clear delimiters or specific instructions to disregard embedded commands within the code scope.
- Capability inventory: The skill has the ability to invoke sub-agents via the
task()function and modify persistent state usingomx. - Sanitization: There is no evidence of filtering or sanitization performed on the code content before it is processed by the AI agents.
Audit Metadata