meta-reviewing-web-reviewing
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious execution patterns, hardcoded credentials, or unauthorized network operations were detected. The skill uses standard markdown and instructional text to define code review patterns.\n- [PROMPT_INJECTION]: The skill is designed to process untrusted external data in the form of React component diffs and JSX/TSX files, which introduces a surface for indirect prompt injection.\n
- Ingestion points: React component source code and PR diffs provided by users for review in files such as
SKILL.md.\n - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the code being reviewed.\n
- Capability inventory: The skill provides instructions for the agent to analyze code structure, logic, and accessibility patterns.\n
- Sanitization: The skill does not implement explicit sanitization or filtering of the input code, relying instead on the agent's baseline safety protocols.
Audit Metadata