reviewing-a-change
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as an extensive set of instructions for an AI agent to conduct code reviews. It uses a modular structure to load specific checklists for various domains including security, concurrency, and performance.
- [SAFE]: All external URL references identify well-known and trusted technology organizations, security standards bodies (e.g., OWASP, NIST), and reputable academic or industry research sources. These are used to provide the agent with authoritative context for its analysis.
- [SAFE]: The skill incorporates explicit instructions to treat all input data (code diffs, PR descriptions, and tool metadata) as untrusted content, effectively mitigating risks associated with indirect prompt injection during the review process.
- [SAFE]: There are no patterns of automated command execution, remote script downloads, or unauthorized access to sensitive local files. The skill's operation is limited to internal logic and data processing as part of the code review workflow.
Audit Metadata