security-code-review

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted code from GitHub pull requests, creating a surface for indirect prompt injection attacks.
  • Ingestion points: External source code and PR metadata retrieved from GitHub (SKILL.md).
  • Boundary markers: None. The template does not include instructions to the agent to distinguish between the provided instructions and the potentially malicious instructions embedded in the reviewed code.
  • Capability inventory: The skill uses a GitHub connection to retrieve repository data.
  • Sanitization: No sanitization or filtering of the processed PR data is mentioned or implemented.
  • [NO_CODE]: The skill contains only informational markdown content and instructions; it does not include any executable scripts, binaries, or automated tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — security-code-review