Review agent · Platform & AI

AI / LLM safety

Checks LLM application code for prompt injection and unsafe handling of model output.

agent/run.py1page = fetch(user_url).text2prompt = SYSTEM + page3cmd = llm(prompt).text4subprocess.run(cmd, shell=True)AIwhat this review answersUntrusted text mixed into prompts?Model output driving tools or shell?Output validated before it acts?$ verdict REAL ISSUE$ fix separate content, validate output▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

Prompt injection is number one in the OWASP Top 10 for LLM Applications. Once a model can call tools, injected text becomes injected actions.

Traditional scanners don't model this at all. This agent looks at where untrusted text enters a prompt and where model output is executed or trusted.

What it checks

  • Untrusted text (user input, fetched pages, files) concatenated into prompts
  • Model output executed, or passed into tool, shell or SQL calls
  • Model output trusted without validation
  • Agent tools broader than the task needs

When it marks a finding as a likely false positive

  • Trusted instructions are separated from untrusted content
  • Output is validated before it drives an action

The fix it suggests

  • Separating instructions from untrusted content
  • Validating and constraining model output
  • Scoping agent tools narrowly

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

How is this different from the agent-setup review?

This agent reviews LLM application code flagged by scanners. The agent-setup reviewer inspects your agent configuration — CLAUDE.md, skills, hooks, MCP servers — as a whole.

Related agents

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the AI / LLM safety agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free