quality-code-review
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of instructional markdown content. It does not include any scripts, executable commands, or external package dependencies.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to process untrusted data in the form of code diffs and pull requests. While the instructions are benign, this creates an attack surface for indirect prompt injection if the code being reviewed contains instructions specifically crafted to deceive the agent.
- Ingestion points: Code diffs, PR descriptions, and source code files provided by the user for review.
- Boundary markers: None explicitly defined in the checklist.
- Capability inventory: No scripts or tool invocations are present in the skill.
- Sanitization: None described in the text.
- [COMMAND_EXECUTION]: There are no shell commands, subprocess calls, or dynamic execution patterns present in the skill instructions.
Audit Metadata