coderabbit
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill guides the agent to execute the
cr(CodeRabbit) CLI tool for various tasks including authentication, reviewing code changes, and checking status. These are documented functionalities of a well-known developer tool. - [EXTERNAL_DOWNLOADS]: Mentions the
cr updatecommand, which is a standard mechanism for updating the CLI tool from its official source. - [INDIRECT_PROMPT_INJECTION]: The skill involves the agent processing local code changes and project context files (such as
.coderabbit.yaml). These files constitute an external data source that could theoretically contain adversarial instructions designed to influence the AI's review behavior.
Audit Metadata