code-review-and-quality
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of markdown-based documentation and instructions for performing code reviews across correctness, readability, architecture, security, and performance dimensions.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing untrusted external data (code changes). While this creates a potential surface for indirect prompt injection, the risk is inherent to the skill's primary purpose, and the instructions explicitly guide the agent to evaluate security and treat external inputs as untrusted.
- Ingestion points: Code snippets, pull request descriptions, and diffs provided to the agent for evaluation.
- Boundary markers: The instructions do not specify explicit delimiters for code content, though they recommend distinct review steps.
- Capability inventory: This instruction-only skill does not list any tool requirements or executable scripts.
- Sanitization: The instructions mandate that reviewers treat data from external sources as untrusted and validate it at system boundaries.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or network operations were detected in the instructions.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill provides guidelines for agents to audit dependencies (e.g., using
npm audit) but does not execute any installation or remote scripts itself.
Audit Metadata