compliance-code-review
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains no executable code, scripts, or binary assets. It is a text-based instruction set for structuring AI agent responses during code reviews.
- [DATA_EXFILTRATION]: No network exfiltration or unauthorized data access patterns were identified. The skill operates within the scoped GitHub connection provided by the platform for the purpose of code review.
- [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private identifiers are present in the skill content.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote code, packages, or external scripts.
- [PROMPT_INJECTION]: The skill evaluates external code from GitHub Pull Requests, creating an attack surface for indirect prompt injection. 1. Ingestion points: Code and metadata pulled from the GitHub repository and PR number. 2. Boundary markers: The prompt template does not define explicit delimiters to isolate untrusted PR content. 3. Capability inventory: The skill is restricted to code analysis and report generation (CODE_REVIEW feature). 4. Sanitization: No explicit sanitization or instructions to ignore embedded commands in the reviewed code are present. The risk is assessed as safe given the lack of dangerous capabilities.
Audit Metadata