critical-code-reviewer
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted code provided by users, which serves as a potential surface for indirect prompt injection. The agent is instructed to analyze external code which could contain instructions aimed at subverting the agent's persona or logic. However, given the skill's primary function and lack of high-risk capabilities, this is considered a standard operational risk.\n
- Ingestion points: User-submitted code snippets and pull request content ingested for review.\n
- Boundary markers: No explicit markers or instructions are provided to the agent to ignore instructions embedded within the processed code.\n
- Capability inventory: Capabilities are limited to generating text feedback and using the
AskUserQuestiontool; no file-writing or network-execution capabilities were identified.\n - Sanitization: There are no documented steps for sanitizing or filtering external code artifacts before processing.
Audit Metadata