code-reviewer

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a markdown instruction file defining a code review checklist. It does not include any scripts, shell commands, or network operations.\n- [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it reviews external content supplied via the $ARGUMENTS variable. Ingestion point: $ARGUMENTS placeholder in SKILL.md; Boundary markers: Absent; Capability inventory: None; the frontmatter specifies disable-model-invocation: true, preventing tool use; Sanitization: Absent. This surface is not exploitable due to the lack of capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 02:37 PM
Security Audit — agent-trust-hub — code-reviewer