review-backend-change

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed purely for static analysis and reporting. It explicitly instructs the agent to avoid mutating environments, changing PR states, or posting comments, adhering to the principle of least privilege.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data in the form of code diffs and backend logic.
  • Ingestion points: User-supplied code diffs and repository files are read during the 'Review flow'.
  • Boundary markers: None explicitly defined for untrusted input data.
  • Capability inventory: Limited to text-based reporting and analysis; no file-writing, network, or subprocess capabilities are utilized or requested.
  • Sanitization: None. While an attacker could embed instructions within a code diff to bias the review, the lack of side-effect capabilities renders this risk negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 03:39 PM
Security Audit — agent-trust-hub — review-backend-change