fix-review
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional and does not include any scripts or executable files. All instructions provided are aligned with standard security code review practices.
- [PROMPT_INJECTION]: The skill is designed to analyze external data such as code commits and audit findings, which represents an indirect prompt injection surface. However, the risk is negligible because the skill possesses no capabilities (such as file system access or network requests) to exploit.
- Ingestion points: External code commits and audit reports provided at runtime for review (SKILL.md).
- Boundary markers: None; the instructions do not include delimiters to isolate untrusted commit data.
- Capability inventory: None; no scripts or tools are associated with this skill (metadata.json: has_scripts=false).
- Sanitization: None; the skill relies on the agent's baseline security model.
Audit Metadata