skills/exaby73/skills/code-reviewer/Gen Agent Trust Hub

code-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions (Establish the review contract, steps 2 and 3) direct the agent to resolve and follow policies found in AGENTS.md files within the target repository and its ancestor directories. This creates an indirect prompt injection surface where the repository under review can provide instructions that bias or manipulate the agent's conclusions.\n
  • Ingestion points: SKILL.md (Establish the review contract, steps 2 and 3).\n
  • Boundary markers: Absent; there are no instructions to differentiate between the data being reviewed and the instructions discovered in the repository's policy files.\n
  • Capability inventory: The agent is instructed to read files, analyze diffs, and issue review conclusions (Approved/Request changes).\n
  • Sanitization: Absent; the skill explicitly requires the agent to 'Follow review policies' sourced from the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:40 PM
Security Audit — agent-trust-hub — code-reviewer