honey-review
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill instructions are focused on analyzing code diffs for optimization and provide clear constraints on what should not be flagged, specifically exempting sensitive areas like authentication, secrets handling, and error handling.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of code diffs. While this represents an ingestion surface for potentially malicious instructions embedded in comments or code within the diff, the skill's lack of actionable capabilities (it only outputs a terse text report for human review) and its strictly defined output format mitigate risks. The instructions explicitly state the output is for a person, not an agent.
Audit Metadata