review-proposal

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's operations are restricted to the local file system, specifically reading and writing markdown artifacts within a project's documentation structure. It does not perform any network requests.
  • [SAFE]: No external dependencies, remote script downloads, or dynamic code execution patterns were identified.
  • [SAFE]: The instructions explicitly implement a read-only policy for inputs and a no-commit policy for outputs, which prevents unintended modifications to the source material or repository history.
  • [SAFE]: The skill processes untrusted user-provided content (proposals and decision logs). While this represents a surface for indirect prompt injection, the impact is minimized because the skill's output is limited to generating a static review report without the ability to trigger system-level commands or access sensitive data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 11:08 AM
Security Audit — agent-trust-hub — review-proposal