review-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional, providing guidelines and examples for a code review task. It does not contain executable scripts or perform network operations.
  • [DATA_EXPOSURE]: The skill includes a proactive 'SECRET SAFETY' rule in its instructions. This rule explicitly forbids the agent from reproducing any hard-coded secrets, tokens, or credentials it might find during a code review, instead requiring redaction. This is a security best practice.
  • [INDIRECT_PROMPT_INJECTION]: Because the skill is designed to ingest and analyze external source code, it possesses a standard vulnerability surface for indirect prompt injection (e.g., instructions hidden in code comments). However, the skill provides a structured framework for analysis which helps keep the agent focused on its primary role.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:23 PM
Security Audit — agent-trust-hub — review-architecture