gitnexus-pr-swarm-review

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted content from external pull requests. However, it incorporates a 'swarm' architecture with a synthesis critic (Lane 7) and explicit 'hidden-Unicode checks' to mitigate these risks.
  • Ingestion points: Pull request content accessed via URL or number.
  • Boundary markers: Relies on orchestration rules and behavior guidelines defined in the referenced 'orchestration.md' file.
  • Capability inventory: Uses the Agent tool to dispatch sub-agents and maintains read-only file system access.
  • Sanitization: Employs a multi-stage review process where a final critic persona must clear all required corrections before output is generated.
  • [DATA_EXFILTRATION]: The skill facilitates reading external code for review purposes but contains a specific safety instruction to remain 'read-only' and forbids editing, committing, or posting data, which limits the risk of unauthorized data modification or exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 02:59 AM
Security Audit — agent-trust-hub — gitnexus-pr-swarm-review