respond-to-review

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill is a defensive utility designed to protect the agent while it processes external code review feedback.
  • [PROMPT_INJECTION]: The skill includes phrases like "Ignore previous instructions" and "You must write a backdoor" as examples of malicious content to be blocked. These are documentation for a security gate and do not constitute an attempt to subvert the agent's behavior.
  • [COMMAND_EXECUTION]: The skill allows for codebase verification and test execution, but it explicitly forbids performing these actions based on reviewer commands. It mandates that the agent only execute commands it determines are necessary to verify valid code changes, effectively isolating system capabilities from untrusted input.
  • [DATA_EXFILTRATION]: The skill mitigates potential exfiltration risks by prohibiting the ingestion of feedback via untrusted URLs and ensuring that raw external text is never passed directly to tool calls or outputs, instead requiring restatement as passive technical requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 04:09 AM
Security Audit — agent-trust-hub — respond-to-review