code-review

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a complex framework for performing code reviews across various dimensions including correctness, concurrency, and security. No malicious behaviors were detected in the skill's own instructions or logic.- [PROMPT_INJECTION]: The skill contains robust defensive instructions (Verification #11 and Theme 25) that explicitly mandate treating all reviewed code, comments, and diff text as untrusted data rather than instructions, effectively mitigating potential injection attempts in the content being reviewed.- [DATA_EXFILTRATION]: The skill includes built-in security auditing rules (Theme 4.4 and SEC-07) to detect leaked secrets, PII, and uninitialized memory within the code being analyzed as part of its review process.- [INDIRECT_PROMPT_INJECTION]: As a tool designed to process untrusted external code, it acknowledges the surface for indirect prompt injection and implements boundary enforcement by mandating that reviewed content is never treated as authoritative instructions.- [COMMAND_EXECUTION]: The skill utilizes standard system tools like bash, grep, and edit_file to perform its primary function of code analysis and patching, which are consistent with the user-invocable nature of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — code-review