integration-review

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • Standard Command Execution: The skill utilizes common developer tools such as gh, git, grep, and mkdocs to manage documentation reviews. These tools are used within their standard contexts for viewing pull requests, checking file statuses, and rendering documentation previews.
  • Access to Repository Content: To perform its review, the skill accesses pull request diffs and local repository files. While this involves reading external or contributor-provided content, it is restricted to the specific task of validating documentation correctness and style within the project environment.
  • Verification of External Dependencies: The skill includes instructions to verify the existence and details of packages on registries like PyPI and npm. This is a security-positive practice that helps ensure documentation correctly references valid, existing software libraries.
  • Indirect Data Processing: As a review tool, the skill processes Markdown content and code snippets provided in pull requests. This represents a potential interface for indirect instructions, which the skill mitigates by providing a rigorous checklist for manual and automated verification by the agent and the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 02:43 AM
Security Audit — agent-trust-hub — integration-review