code-critique
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a collection of natural language instructions for code analysis. No malicious patterns, obfuscation, or unauthorized data access were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of code and pull requests. While this creates a potential surface for indirect prompt injection, the risk is negligible as the skill does not define any executable capabilities, tool usage, or network operations that could be exploited by malicious input. * Ingestion points: Processes code, diffs, and pull requests as described in SKILL.md. * Boundary markers: None identified in the prompt instructions. * Capability inventory: No tool usage, shell commands, or network operations are defined in the skill or its configuration. * Sanitization: No specific sanitization or filtering of input code is defined.
Audit Metadata