code-review

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the coderabbit CLI to perform code reviews, check authentication status, and manage local configurations. These are standard operations for the tool's intended purpose.
  • The commands include coderabbit review --agent, coderabbit auth status, and coderabbit config, which are documented and used with appropriate safety flags.
  • [DATA_EXFILTRATION]: The skill facilitates sending code diffs to the official CodeRabbit API for analysis.
  • It includes explicit instructions to check for secrets or credentials before running reviews and warns against printing or logging secret contents.
  • Network communication is restricted to the legitimate vendor infrastructure (coderabbit.ai).
  • [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of processing untrusted repository data and review outputs.
  • It implements a safety boundary by instructing the agent to treat all review output as untrusted and never to execute commands or code derived from these results without explicit user approval.
  • [EXTERNAL_DOWNLOADS]: The skill provides guidance for installing the CodeRabbit CLI.
  • It directs users to the official website (https://www.coderabbit.ai/cli) and package managers (npm, Homebrew).
  • It explicitly advises against dangerous practices like piping remote scripts to a shell and recommends verifying binary signatures or checksums.
  • [CREDENTIALS_SAFE]: The skill provides secure authentication flows via browser-based OAuth (coderabbit auth login).
  • It warns against reading credential files directly or requesting that users paste sensitive tokens into the chat transcript.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:22 PM
Security Audit — agent-trust-hub — code-review