plan-reviewer
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions are focused entirely on the intended task of reviewing implementation work. No patterns of prompt injection, data exfiltration, or unauthorized command execution were found.
- [SAFE]: The skill defines strict boundaries (e.g., forbidding edits to core project files like
project-graph.jsonorstate.json), which acts as a security guardrail against accidental or malicious modifications to the project structure. - [SAFE]: While the skill involves processing external data (implementation reports, changed files), this is the primary function of a reviewer. The instructions include specific checks to ensure the reviewer verifies evidence and checks for uncalled or mock paths, which helps mitigate risks associated with untrusted input.
Audit Metadata