review-security-compliance

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill establishes a comprehensive framework for security audits, focusing on authentication boundaries, sensitive data handling, and tenant isolation.
  • [SAFE]: Operational guardrails are in place to ensure the agent does not modify code without authorization and remains focused on evidence-based analysis.
  • [SAFE]: No indicators of data exfiltration, credential theft, or unauthorized network access were found. The skill operates locally on the provided code context.
  • [SAFE]: While the skill can run verification commands, this capability is restricted to confirming security findings during the review process and no dangerous pre-configured commands were detected.
  • [SAFE]: The skill inherently processes untrusted data (external code changes), which represents a potential indirect prompt injection surface. However, this is a standard functional requirement for a code review tool and is mitigated by the structured output and oversight rules defined in the skill.
  • Ingestion points: Analyzes project files and code diffs in the repository context.
  • Boundary markers: None explicitly defined for untrusted code inputs.
  • Capability inventory: Filesystem read access and execution of shell-based verification commands.
  • Sanitization: No specific sanitization of input code is described, but findings are constrained by a defined severity model.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 03:55 PM
Security Audit — agent-trust-hub — review-security-compliance