ia-code-review

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a managed surface for indirect prompt injection, which is necessary for its primary function of reviewing untrusted code. Boundary markers such as 'DIFF:', 'PR INTENT:', and 'SCOPE:' are used in agent templates to separate code from instructions. Ingestion points include git and GitHub CLI tools, and the capability inventory is limited to standard repository interactions and agent dispatches. Basic sanitization is applied for markdown compatibility.
  • [SAFE]: Repository interaction and comparison-range resolution are performed using standard tools (git, gh). The skill follows a non-destructive protocol, explicitly warning against commands that mutate the user's working tree (e.g., git reset, git clean) and providing safe alternatives for branch reviews.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 06:03 PM
Security Audit — agent-trust-hub — ia-code-review