receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides interaction instructions aimed at ensuring technical correctness during code review processes. It specifically targets the reduction of 'blind implementation' of potentially incorrect or unnecessary suggestions.
- [COMMAND_EXECUTION]: The skill references standard development tools including
grepfor searching the codebase and theghCLI (gh api) for interacting with GitHub Pull Request comments. These tools are used within their intended scope for software development tasks. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent on how to handle untrusted data in the form of external code review feedback.
- Ingestion points: Feedback received from human partners and external reviewers, specifically via GitHub comments.
- Boundary markers: The skill does not define technical delimiters for the feedback but provides logical boundaries by requiring the agent to 'Verify before implementing'.
- Capability inventory: The agent is authorized to use
grepfor reading the codebase andgh apifor network-based communication to post replies. - Sanitization: There is no automated sanitization of the input; instead, the skill provides a behavioral framework (skepticism and verification) to prevent the agent from being manipulated by technically incorrect or malicious suggestions.
Audit Metadata