code-review-linus-torvalds-style
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a rigorous framework for technical code reviews focused on correctness and engineering discipline. No malicious instructions, obfuscation, or exfiltration patterns were detected across any of the files.
- [COMMAND_EXECUTION]: The skill uses standard development tools such as
bash,grep, andedit_fileas defined in theSKILL.mdfrontmatter andagents/openai.yaml. These tools are appropriately scoped for the skill's primary function of auditing and refactoring source code within a repository. - [PROMPT_INJECTION]: While the skill instructions use strong language (e.g., "brutal," "merciless," "technically ruthless"), this is part of a role-play framework aimed at improving technical standards rather than bypassing safety filters or overriding agent system prompts. It does not contain instructions to ignore safety guidelines or extract sensitive information.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it is designed to process external code (PRs, diffs, patches). The
SKILL.mdincludes a [REASON] → [ACT] protocol and strict verification steps to mitigate the risk of accidental obedience to instructions embedded in the code under review. The overall severity for this attack surface is low. - [DATA_EXPOSURE]: There are no hardcoded credentials or attempts to access sensitive system paths (e.g.,
.ssh,.aws). The skill focuses exclusively on the source code and invariants of the project being reviewed.
Audit Metadata