receiving-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and process code review feedback from 'External Reviewers', which constitutes an attack surface where an attacker could embed malicious instructions in PR comments.
  • Ingestion points: External code review feedback and GitHub PR comments (as referenced in SKILL.md under 'From External Reviewers' and 'GitHub Thread Replies').
  • Capability inventory: The skill allows the agent to grep the codebase, use the GitHub API (gh api), and implement changes (file-write capabilities implied by the 'IMPLEMENT' step).
  • Boundary markers: Absent; there are no specific markers used to delimit external feedback from internal instructions.
  • Sanitization: Absent; the skill does not specify sanitization or filtering of the incoming review text before the agent evaluates it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — receiving-code-review