project-review
Pass
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data including project source code and git differences. While this presents an ingestion surface for indirect prompt injection, the risk is inherent to the primary purpose of code review.
- [COMMAND_EXECUTION]: The skill instructs the agent to perform technical verification using existing local tools such as
build,lint,type check, and test suites. These are standard operations within a development environment and are triggered within the context of reviewing code implementation.
Audit Metadata