ddd-code-reviewer
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The file 'references/06-gotchas.md' contains several shell command examples (using grep, awk, sort, and uniq) designed for identifying architectural violations in local Java source code. These commands are benign and directly support the skill's code-review purpose.
- [PROMPT_INJECTION]: This skill's primary function is to analyze untrusted source code, creating an inherent attack surface for indirect prompt injection. The skill mitigates accidental execution by using defined report templates. Evidence: Ingestion points (user-supplied code fragments or repository paths in 'SKILL.md'); Boundary markers (none explicitly defined to isolate code content); Capability inventory (local shell commands for pattern matching); Sanitization (no specific validation or filtering methods mentioned).
Audit Metadata