code-review-linus-torvalds-style

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a rigorous framework for technical code reviews focused on correctness and engineering discipline. No malicious instructions, obfuscation, or exfiltration patterns were detected across any of the files.
  • [COMMAND_EXECUTION]: The skill uses standard development tools such as bash, grep, and edit_file as defined in the SKILL.md frontmatter and agents/openai.yaml. These tools are appropriately scoped for the skill's primary function of auditing and refactoring source code within a repository.
  • [PROMPT_INJECTION]: While the skill instructions use strong language (e.g., "brutal," "merciless," "technically ruthless"), this is part of a role-play framework aimed at improving technical standards rather than bypassing safety filters or overriding agent system prompts. It does not contain instructions to ignore safety guidelines or extract sensitive information.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it is designed to process external code (PRs, diffs, patches). The SKILL.md includes a [REASON] → [ACT] protocol and strict verification steps to mitigate the risk of accidental obedience to instructions embedded in the code under review. The overall severity for this attack surface is low.
  • [DATA_EXPOSURE]: There are no hardcoded credentials or attempts to access sensitive system paths (e.g., .ssh, .aws). The skill focuses exclusively on the source code and invariants of the project being reviewed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 05:53 AM
Security Audit — agent-trust-hub — code-review-linus-torvalds-style