liveview-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a set of documentation and instructional guidelines for code review. It does not contain executable scripts, shell commands, or network operations.
  • [SAFE]: Security recommendations in references/security.md correctly advocate for server-side authorization and input validation, using educational 'BAD' vs 'GOOD' examples to highlight vulnerabilities like over-trusting phx-value or exposing secrets in assigns.
  • [SAFE]: No obfuscation, prompt injection attempts, or persistence mechanisms were detected. The 'Hard gates' section in SKILL.md provides logical constraints to ensure the agent bases its findings on actual code evidence.
  • [SAFE]: The skill refers to standard Phoenix framework patterns (e.g., connected?(socket), AsyncResult, phx-update="stream") and follows secure-by-default development principles.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — liveview-code-review