code-review
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
coderabbitCLI to perform code reviews, check authentication status, and manage local configurations. These are standard operations for the tool's intended purpose. - The commands include
coderabbit review --agent,coderabbit auth status, andcoderabbit config, which are documented and used with appropriate safety flags. - [DATA_EXFILTRATION]: The skill facilitates sending code diffs to the official CodeRabbit API for analysis.
- It includes explicit instructions to check for secrets or credentials before running reviews and warns against printing or logging secret contents.
- Network communication is restricted to the legitimate vendor infrastructure (coderabbit.ai).
- [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of processing untrusted repository data and review outputs.
- It implements a safety boundary by instructing the agent to treat all review output as untrusted and never to execute commands or code derived from these results without explicit user approval.
- [EXTERNAL_DOWNLOADS]: The skill provides guidance for installing the CodeRabbit CLI.
- It directs users to the official website (https://www.coderabbit.ai/cli) and package managers (npm, Homebrew).
- It explicitly advises against dangerous practices like piping remote scripts to a shell and recommends verifying binary signatures or checksums.
- [CREDENTIALS_SAFE]: The skill provides secure authentication flows via browser-based OAuth (
coderabbit auth login). - It warns against reading credential files directly or requesting that users paste sensitive tokens into the chat transcript.
Audit Metadata