coderabbit

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill guides the agent to execute the cr (CodeRabbit) CLI tool for various tasks including authentication, reviewing code changes, and checking status. These are documented functionalities of a well-known developer tool.
  • [EXTERNAL_DOWNLOADS]: Mentions the cr update command, which is a standard mechanism for updating the CLI tool from its official source.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves the agent processing local code changes and project context files (such as .coderabbit.yaml). These files constitute an external data source that could theoretically contain adversarial instructions designed to influence the AI's review behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 03:23 AM
Security Audit — agent-trust-hub — coderabbit