cmd-codex-review-unstaged
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements secure temporary file management by using
mktempto create isolation andrmto ensure that sensitive diffs and summaries are deleted after processing. - [SAFE]: The skill uses defense-in-depth by enforcing a
--sandbox read-onlyconstraint on the external reviewer utility, which prevents the sub-process from modifying any project files. - [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it processes raw git diff data which could contain malicious instructions embedded in comments or code.
- Ingestion points: Untrusted data is ingested from the project repository through the
git diff HEADcommand inSKILL.md. - Boundary markers: The skill uses clear labels within the reviewer's prompt to delineate between the agent-provided summary and the external diff content.
- Capability inventory: The skill utilizes shell commands for file management and git operations, and invokes an external review tool.
- Sanitization: There is no evidence of sanitization or character filtering performed on the git diff output before it is passed to the reviewer.
Audit Metadata