address-review

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted data from external sources such as files, PRs, or comments (Step 1).
  • Ingestion points: Findings sourced from files, PR comments, or session context in SKILL.md.
  • Boundary markers: No specific delimiters or safety instructions are defined for the ingested review content.
  • Capability inventory: The skill can implement code fixes, commit changes, and push to remote branches (Steps 3 & 4).
  • Sanitization: While no technical sanitization is mentioned, the 'Triage' phase (Step 2) acts as a critical mitigation by requiring the user to manually review and approve the disposition of each finding before any action is taken.
  • [COMMAND_EXECUTION]: The skill is designed to perform file system modifications and git operations (commit, push). These actions are consistent with the skill's stated purpose of actioning code reviews and are gated by the user triage process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 05:02 AM
Security Audit — agent-trust-hub — address-review