react-nextjs-review
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of markdown-based instructions and checklists for code review. It does not include any scripts, executables, or commands that could be misused.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external data (code diffs and pull requests). This represents a vulnerability surface where an attacker could embed malicious instructions within code comments or string literals to influence the agent's review verdict. However, the skill does not have capabilities for autonomous code execution or network exfiltration, which significantly limits the risk of this attack surface.
Audit Metadata