code-review-and-quality

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of code diffs and pull requests for review purposes. This creates a surface where a malicious actor could attempt to embed instructions within the code content to influence the agent's behavior.
  • Ingestion points: Code diffs, pull request descriptions, and inline code snippets processed during the review flow as described in SKILL.md.
  • Boundary markers: The skill does not explicitly define delimiters or instructions to ignore embedded commands within the code under review.
  • Capability inventory: The skill provides instructions for an agent that typically operates in an environment with file system access and code analysis capabilities.
  • Sanitization: No specific sanitization, validation, or escaping of the ingested code content is defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 04:29 AM
Security Audit — agent-trust-hub — code-review-and-quality