compliance-code-review

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no executable code, scripts, or binary assets. It is a text-based instruction set for structuring AI agent responses during code reviews.
  • [DATA_EXFILTRATION]: No network exfiltration or unauthorized data access patterns were identified. The skill operates within the scoped GitHub connection provided by the platform for the purpose of code review.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private identifiers are present in the skill content.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote code, packages, or external scripts.
  • [PROMPT_INJECTION]: The skill evaluates external code from GitHub Pull Requests, creating an attack surface for indirect prompt injection. 1. Ingestion points: Code and metadata pulled from the GitHub repository and PR number. 2. Boundary markers: The prompt template does not define explicit delimiters to isolate untrusted PR content. 3. Capability inventory: The skill is restricted to code analysis and report generation (CODE_REVIEW feature). 4. Sanitization: No explicit sanitization or instructions to ignore embedded commands in the reviewed code are present. The risk is assessed as safe given the lack of dangerous capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — compliance-code-review