code-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute local Python scripts (pr_analyzer.py, code_quality_checker.py, review_report_generator.py) located within the skill directory. These scripts use standard Python libraries (argparse, pathlib, json) to process files at a user-specified path and do not exhibit dangerous command execution patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and analyze external data (source code and PR diffs). This constitutes a potential attack surface where malicious instructions could be embedded in the code being reviewed. However, the skill specifies structured output formats and uses boundary markers in its reporting, which mitigates the risk. The current script implementations are placeholders that do not execute the content of the files they analyze.
  • [SAFE]: No evidence of data exfiltration, hardcoded credentials, obfuscation, or persistence mechanisms was found. The skill limits its capabilities through the allowed-tools configuration and targets well-defined review workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:07 PM
Security Audit — agent-trust-hub — code-reviewer