code-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze untrusted data from source code files and pull request diffs, which creates a potential surface for indirect prompt injection.
- Ingestion points: External code content and diffs are accessed using the
Read,Grep, andGlobtools as specified inSKILL.md. - Boundary markers: The instructions do not implement specific delimiters or warnings to ignore instructions embedded within the code being reviewed.
- Capability inventory: The skill's capabilities are restricted to read-only file operations (
Read,Grep,Glob) and it lacks dangerous tools for network communication, file writing, or command execution. - Sanitization: The skill does not include specific logic to sanitize or escape the content of the files it reads before processing them in the agent's context.
Audit Metadata