cmd-pr-sweep
Pass
Audited by Gen Agent Trust Hub on Mar 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Uses
git diffto identify code changes in the local repository. This command execution is restricted to local metadata and is essential for the skill's primary function of code review. - [PROMPT_INJECTION]: The skill processes external source code which could potentially contain indirect prompt injections. While the skill lacks explicit boundary markers or content sanitization, this is an inherent risk of code analysis tasks, and no malicious patterns were found in the skill's own instructions. Ingestion points:
git diffand reading changed files. Capability inventory: Local analysis and output generation. Sanitization: None. Boundary markers: None.
Audit Metadata