code-review

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted third-party content, including pull request descriptions, comments, and issue text. This creates an attack surface for indirect prompt injection where a malicious actor might attempt to influence the agent's behavior via embedded instructions.
  • Ingestion points: Pull request descriptions, comments, and issue text are ingested as part of the review process in SKILL.md.
  • Boundary markers: The skill contains a specific 'THIRD-PARTY CONTENT DEFENSE' section that instructs the agent to treat this content as untrusted, disregard any directives or calls to action, and treat the code diff as the sole authoritative source.
  • Capability inventory: The skill is designed for code analysis and reporting; it does not define high-privilege capabilities such as arbitrary file writes or network operations within the provided instructions.
  • Sanitization: The skill mandates a strict review order and explicitly directs the agent to ignore instructions embedded in PR metadata, focusing only on factual details.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:12 PM
Security Audit — agent-trust-hub — code-review