code-review-excellence

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documentation and provided scripts are benign and follow standard software development practices. No malicious code, obfuscation, or persistence mechanisms were found.
  • [COMMAND_EXECUTION]: The script scripts/pr-analyzer.py uses subprocess.run to execute the git command for calculating diff statistics. It correctly uses a list of arguments and defaults to shell=False, which prevents shell injection attacks. Access is limited to the local filesystem for repository analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it is intended to process untrusted code diffs and pull request descriptions. Ingestion points include the pull request content reviewed by the agent and processed by scripts/pr-analyzer.py. The skill lacks explicit boundary markers or sanitization for this external data, but its capabilities (file analysis and comment generation) do not provide a direct path for high-severity exploitation. This risk is inherent to the skill's purpose and mitigated by the structured review instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:01 AM