review-core

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a structural template for independent reviewers and does not contain executable code, remote downloads, or credential-accessing commands.
  • [PROMPT_INJECTION]: The skill defines a process for analyzing external code, which constitutes an indirect prompt injection surface.
  • Ingestion points: Files read during the review process (SKILL.md).
  • Boundary markers: Absent.
  • Capability inventory: File system read access for code analysis and write access to the .agent-memory/ directory for findings.
  • Sanitization: No explicit sanitization or instruction-guarding delimiters are defined for processing ingested code. Note: This surface is necessary for the skill's intended purpose as a code review tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 06:31 AM
Security Audit — agent-trust-hub — review-core