receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process code review feedback from external reviewers, creating an attack surface for indirect prompt injection.
- Ingestion points: Processes feedback strings from external reviewers during the code review process (SKILL.md).
- Boundary markers: The instructions do not define clear delimiters or include warnings to ignore instructions embedded within the feedback data.
- Capability inventory: The skill utilizes
gh apifor network communication (responding to GitHub threads) andgrepfor searching the codebase (SKILL.md). - Sanitization: There is no evidence of content sanitization or validation logic for the incoming review feedback.
- [METADATA_POISONING]: There is an inconsistency in authorship attribution. The LICENSE.txt file credits Jesse Vincent and Osmany Montero, while the skill metadata identifies 1git2clone as the author.
Audit Metadata