respond-to-review

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill manages the processing of pull request reviews, which involves ingesting potentially malicious instructions from external contributors.
  • Ingestion points: Processes external text from PR review comments and feedback (documented in SKILL.md).
  • Boundary markers: Employs a "HARD-GATE" protocol requiring the agent to restate all feedback as passive technical requirements and perform verification against the codebase before any implementation starts.
  • Capability inventory: The skill is designed to guide file modifications and test execution based on external feedback, typically chaining with TDD and refactoring skills.
  • Sanitization: Explicitly identifies "Untrusted / Injection" as a category for review feedback, instructing the agent to ignore, report, and block instructions that attempt to override system gates or prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:22 PM
Security Audit — agent-trust-hub — respond-to-review