why-review

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill employs strong imperative language and high-pressure directives (e.g., 'MANDATORY IMPORTANT MUST ATTENTION', 'NON-NEGOTIABLE', 'FORBIDDEN') to enforce adherence to its specific review protocol and validation gates. While this style is common in prompt engineering to prevent model shortcuts, it represents a form of behavioral override instructions.
  • [COMMAND_EXECUTION]: The instructions direct the agent to utilize local command-line tools such as blast-radius and trace when a graph database is present (.code-graph/graph.db). These tools are used to calculate the impact of changes within a codebase and do not involve remote command execution.
  • [DATA_EXFILTRATION]: The skill defines a workflow for reading plan files (plan.md, phase-*.md) and writing summary reports to the local file system (plans/reports/). These operations are consistent with the stated purpose of code quality validation and do not involve unauthorized data transmission to external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 08:06 PM