thermo-nuclear-code-quality-review
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of instructional content for performing code reviews. It contains no executable scripts, tool configurations, or network-enabled operations.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data including pull request descriptions, commit messages, and source code. While this constitutes an attack surface for indirect prompt injection, the risk is mitigated to a safe level because the skill possesses no capabilities that could be abused.
-
- Ingestion points: PR descriptions, commit messages, and code snippets (SKILL.md).
-
- Boundary markers: Absent.
-
- Capability inventory: No tool access, network operations, or file-writing capabilities are defined.
-
- Sanitization: Absent.
Audit Metadata