code-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs shell command execution to manage the code review workflow, utilizing git status, git diff, gh pr checkout for GitHub integration, and npm run preflight to execute project-defined verification scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, which may contain instructions intended to manipulate the agent's behavior during the review process.
  • Ingestion points: The skill reads Pull Request descriptions, existing comments, and code diffs as described in the Workflow section of SKILL.md.
  • Boundary markers: Absent. No specific delimiters or instructions are provided to the agent to disregard instructions found within the reviewed code or PR metadata.
  • Capability inventory: The skill has access to shell execution (git, gh, npm) and file system access through git commands, which could be targeted by an injection attack.
  • Sanitization: There is no evidence of filtering, escaping, or validation of external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:29 PM
Security Audit — agent-trust-hub — code-reviewer