address-stack-feedback

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust, state-driven workflow for managing GitHub pull request stacks. It enforces strict authority boundaries, requiring explicit stack numbers and authenticated identities while preventing unauthorized mutations like merging or repository policy changes. The use of provider adapters, such as the coderabbit_adapter.py, is restricted to specific trigger and completion logic, avoiding common pitfalls like inventing arbitrary timers or paid options. The helper scripts (stack_state.py, coderabbit_adapter.py) use standard library components for networking and file locking. The security posture correctly treats all external review findings and embedded instructions as untrusted claims, requiring factual validation against the integrated stack top. The behavioral tests demonstrate proper handling of edge cases such as head invalidation, rate limiting, and stack topology changes, ensuring the tool behaves predictably and securely within its intended scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:13 AM
Security Audit — agent-trust-hub — address-stack-feedback