code-review-workflow
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a comprehensive instructional guide for AI agents performing code reviews. It includes detailed checklists for security (authentication, injection, XSS, CSRF, secrets), accessibility (WCAG 2.1 AA), and performance.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns, suspicious package installations, or command injection vulnerabilities were identified. The mentioned tools (Vitest, Playwright, MSW, Axe) are standard industry utilities for testing.
- [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or tokens were found. The skill explicitly instructs users to avoid hardcoding secrets and to use environment variables instead.
- [PROMPT_INJECTION]: The instructions do not contain attempts to bypass safety filters or override agent behavior maliciously. The use of 'IMPORTANT' or 'Critical' is contextually appropriate for a code review severity system.
- [DATA_EXFILTRATION]: No network operations to unknown domains or sensitive file access patterns were detected. All described processes focus on local code analysis and reporting within the agent's environment.
- [INDIRECT_PROMPT_INJECTION]: The skill inherently processes untrusted data (source code and PR descriptions). While it lacks explicit boundary markers for this data, its primary purpose is critical analysis of such inputs, and no exploitable capabilities for automated system changes were found. Findings in this category are assessed as safe given the skill's purpose.
Audit Metadata