do-code-review

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes uncommitted code changes from the local repository, which creates a surface for indirect prompt injection where malicious instructions embedded in the reviewed code could influence the agent's behavior. 1. Ingestion points: The agent reads local staged and unstaged files within the 'sdk/ml/azure-ai-ml/' directory via git commands. 2. Boundary markers: The instructions do not define specific delimiters or warnings to ignore embedded prompts within the analyzed source code. 3. Capability inventory: The agent accesses the local file system to read source code and produces detailed technical review reports. 4. Sanitization: No explicit content filtering or validation is performed on the code changes before they are processed by the agent.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill directs the agent to identify and flag security risks such as hardcoded secrets, API keys, and credentials in the source code, which serves as a defensive measure.
  • [EXTERNAL_DOWNLOADS]: The skill references official Azure SDK guidelines and documentation from the author's verified domains and repositories including azure.github.io and GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:49 AM
Security Audit — agent-trust-hub — do-code-review