squad-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional markdown files intended to guide an AI agent through a manual code review process. It does not contain executable scripts or automation that could perform unauthorized actions.- [EXTERNAL_DOWNLOADS]: The skill includes references to official documentation and industry standards from well-known organizations including OWASP, NIST, SLSA, and others. These URLs are provided for informational purposes to support evidence-based reviews and do not trigger automated downloads of executable content.- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes explicit instructions for the agent to protect sensitive information, stating that it should never expose secrets or private payloads in its findings.- [COMMAND_EXECUTION]: The instructions contain strict prohibitions against the automatic installation of skills, scanners, or CLI tools, ensuring the agent remains within its authorized environment.- [INDIRECT_PROMPT_INJECTION]: The skill identifies external inputs such as code comments and PR text as untrusted data and instructs the agent to treat them accordingly, which helps mitigate the risk of the agent following malicious instructions embedded in the code being reviewed.
Audit Metadata