receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill establishes guidelines for receiving and processing code review feedback, focusing on technical verification rather than social compliance.
- [INDIRECT_PROMPT_INJECTION]: The skill includes defensive instructions that mitigate risks from indirect prompt injection in external code reviews. It mandates that the agent verify all external suggestions against the codebase, check for technical correctness, and consult the primary developer before implementing feedback from untrusted sources.
- [COMMAND_EXECUTION]: The skill references the use of standard development tools like
grepfor codebase searching and the GitHub CLI (gh api) for responding to PR comments, which are legitimate use cases for a development-oriented agent.
Audit Metadata