code-review-playbook
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of Pull Request descriptions and comments.
- Ingestion points: Untrusted PR narrative text and code diffs are ingested for analysis in Phase 1 (SKILL.md).
- Boundary markers: The instructions explicitly define the PR text as "untrusted, outsider-authored data" and mandate that the "Diff is sole authority" (SKILL.md).
- Capability inventory: The skill orchestrates report generation, task-list creation, and logic for implementing code fixes (SKILL.md).
- Sanitization: A mandatory "Hard Gate" requires the agent to verify all claims from prose against the branch diff and extract only factual information (SKILL.md).
Audit Metadata