code-review

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructions for the agent to review code diffs. No malicious patterns, network requests, or dangerous commands were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted content (PR diffs and descriptions). This creates a surface for indirect prompt injection, although the risk is minimal as no sensitive tools or execution capabilities are requested.
  • Ingestion points: External PR diffs and descriptions defined in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore commands within the diff are present.
  • Capability inventory: No scripts or tool permissions are defined.
  • Sanitization: No input validation or sanitization logic is included.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 09:40 PM
Security Audit — agent-trust-hub — code-review