skills/heymoezy/porter/code-reviewer/Gen Agent Trust Hub

code-reviewer

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and supporting documentation (SKILL.md, prompt.md) promote high-quality code review practices. No malicious code, hidden commands, or deceptive metadata were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data in the form of code diffs and pull requests (referenced in SKILL.md and meta/skill.json). While this creates a theoretical surface for indirect prompt injection (e.g., malicious instructions hidden in code comments), the skill's instructions strictly focus on generating text-based feedback and do not include capabilities to execute the code being reviewed. The lack of explicit boundary markers is a minor configuration detail that does not compromise the skill's safety given its limited output scope.
  • [DATA_EXPOSURE]: No hardcoded credentials or access to sensitive local file paths (such as .ssh or .aws) were detected across the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 11:46 AM
Security Audit — agent-trust-hub — code-reviewer