review-proposal
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's operations are restricted to the local file system, specifically reading and writing markdown artifacts within a project's documentation structure. It does not perform any network requests.
- [SAFE]: No external dependencies, remote script downloads, or dynamic code execution patterns were identified.
- [SAFE]: The instructions explicitly implement a read-only policy for inputs and a no-commit policy for outputs, which prevents unintended modifications to the source material or repository history.
- [SAFE]: The skill processes untrusted user-provided content (proposals and decision logs). While this represents a surface for indirect prompt injection, the impact is minimized because the skill's output is limited to generating a static review report without the ability to trigger system-level commands or access sensitive data.
Audit Metadata