why-review
Pass
Audited by Gen Agent Trust Hub on Apr 19, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill employs strong imperative language and high-pressure directives (e.g., 'MANDATORY IMPORTANT MUST ATTENTION', 'NON-NEGOTIABLE', 'FORBIDDEN') to enforce adherence to its specific review protocol and validation gates. While this style is common in prompt engineering to prevent model shortcuts, it represents a form of behavioral override instructions.
- [COMMAND_EXECUTION]: The instructions direct the agent to utilize local command-line tools such as
blast-radiusandtracewhen a graph database is present (.code-graph/graph.db). These tools are used to calculate the impact of changes within a codebase and do not involve remote command execution. - [DATA_EXFILTRATION]: The skill defines a workflow for reading plan files (
plan.md,phase-*.md) and writing summary reports to the local file system (plans/reports/). These operations are consistent with the stated purpose of code quality validation and do not involve unauthorized data transmission to external domains.
Audit Metadata