code-review
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns detected. The skill outlines best practices for the code review process.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for handling external feedback, which is an attack surface for indirect prompt injection. However, it incorporates mitigations by instructing the agent to technically verify and evaluate all feedback before taking action.
- Ingestion points: 'External reviewer' and 'Automated tool' feedback entries in the Source-Specific Handling table.
- Boundary markers: The 'Core Principle' and 'Response Pattern' sections explicitly require verification and technical evaluation.
- Capability inventory: The skill itself contains no executable code or tool calls; capabilities depend on the agent's environment (typically file system and command execution during development tasks).
- Sanitization: Instructions require the agent to 'Verify against codebase reality' and 'Ask for clarification' if feedback is unclear.
Audit Metadata