receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides strict behavioral instructions that override default agent communication styles, explicitly forbidding expressions of gratitude or social agreement (e.g., "Great point!") to ensure technical focus.
- [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by instructing the agent to process and implement suggestions from external reviewers. A malicious reviewer could attempt to inject instructions through review comments. The skill mitigates this by instructing the agent to evaluate external feedback skeptically and verify suggestions against the codebase reality before implementation.
- Ingestion points: External reviewer feedback provided via pull request comments.
- Boundary markers: None explicitly defined in the instructions for the external input.
- Capability inventory: The skill references file searching (
grep) and interaction with the GitHub API (gh api). - Sanitization: The skill relies on technical evaluation ("Check: Technically correct for THIS codebase?") rather than automated sanitization.
- [COMMAND_EXECUTION]: The instructions reference the execution of shell commands, specifically
grepfor codebase analysis and the GitHub CLI (gh api) for replying to pull request comments.
Audit Metadata