review-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily instructional, providing guidelines and examples for a code review task. It does not contain executable scripts or perform network operations.
- [DATA_EXPOSURE]: The skill includes a proactive 'SECRET SAFETY' rule in its instructions. This rule explicitly forbids the agent from reproducing any hard-coded secrets, tokens, or credentials it might find during a code review, instead requiring redaction. This is a security best practice.
- [INDIRECT_PROMPT_INJECTION]: Because the skill is designed to ingest and analyze external source code, it possesses a standard vulnerability surface for indirect prompt injection (e.g., instructions hidden in code comments). However, the skill provides a structured framework for analysis which helps keep the agent focused on its primary role.
Audit Metadata