receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill d efine s a su rface for ind irect prom pt in jectio n by instru cting the a gent to pro cess an d act upon instr uction s con taine d wit hin ex terna l cod e rev iew f eedba ck.
- Inges tion p oints: Co de r eview feedb ack fr om ex terna l rev iewer s (SK ILL.m d).
- Boun dary m arker s: No d elimi ters or bo undar y mar kers are d efin ed to isola te un trust ed in put f rom s ystem instr uctio ns.
- Capab ility inven tory: The a gent is i nstru cted t o use
grepand t heghCL I for sear ching code and i ntera cting with GitH ub AP Is (S KILL. md). - Sani tizat ion: No i nput sani tizat ion o r val idati on is speci fied for t he ex terna l fee dback con tent.
- [COMMAND_EXECUTION]: The skill provi des p atter ns fo r exe cutin g Git Hub C LI co mmand s (
gh api) to i ntera ct wi th re posit ory p ull r eques t thr eads .
Audit Metadata