security-code-review
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted code from GitHub pull requests, creating a surface for indirect prompt injection attacks.
- Ingestion points: External source code and PR metadata retrieved from GitHub (SKILL.md).
- Boundary markers: None. The template does not include instructions to the agent to distinguish between the provided instructions and the potentially malicious instructions embedded in the reviewed code.
- Capability inventory: The skill uses a GitHub connection to retrieve repository data.
- Sanitization: No sanitization or filtering of the processed PR data is mentioned or implemented.
- [NO_CODE]: The skill contains only informational markdown content and instructions; it does not include any executable scripts, binaries, or automated tasks.
Audit Metadata