coderabbit-core-workflow-a

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a configuration template and workflow guide for the CodeRabbit service. All instructions provided are standard for setting up automated PR reviews.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation at docs.coderabbit.ai. These references are for informational purposes and point to the well-known domain of the service provider.
  • [PROMPT_INJECTION]: While the skill involves configuring an AI agent's behavior via .coderabbit.yaml (e.g., path_instructions), these are functional settings for the tool's primary purpose and do not contain malicious overrides or bypass attempts.
  • [DATA_EXPOSURE]: The skill provides instructions for reviewing .github/workflows/** files. This is documented as a security best practice (e.g., checking for pinned versions and secret management) rather than an attempt to expose sensitive data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:07 AM
Security Audit — agent-trust-hub — coderabbit-core-workflow-a