code-reviewer
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted code content which creates an indirect prompt injection surface. A malicious contributor could attempt to influence the agent by embedding instructions in code comments. This risk is mitigated by the skill's structured workflow, restricted read-only toolset (Read, Grep, Glob), and the requirement for the agent to summarize intent before beginning a review.
- Ingestion points: Pull request descriptions and source code files accessed via reading tools.
- Boundary markers: The skill uses a 'Core Workflow' and 'Output Template' to maintain focus on technical analysis.
- Capability inventory: Access is restricted to basic file reading and searching; no network or shell execution tools are enabled.
- Sanitization: Not applicable as the skill performs static review rather than execution of the ingested code.
Audit Metadata