code-review-excellence
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documentation and provided scripts are benign and follow standard software development practices. No malicious code, obfuscation, or persistence mechanisms were found.
- [COMMAND_EXECUTION]: The script
scripts/pr-analyzer.pyusessubprocess.runto execute thegitcommand for calculating diff statistics. It correctly uses a list of arguments and defaults toshell=False, which prevents shell injection attacks. Access is limited to the local filesystem for repository analysis. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it is intended to process untrusted code diffs and pull request descriptions. Ingestion points include the pull request content reviewed by the agent and processed by
scripts/pr-analyzer.py. The skill lacks explicit boundary markers or sanitization for this external data, but its capabilities (file analysis and comment generation) do not provide a direct path for high-severity exploitation. This risk is inherent to the skill's purpose and mitigated by the structured review instructions.
Audit Metadata