audit-code-review
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill follows its stated purpose of assisting with code reviews and security audits without including any malicious instructions or hidden behaviors.
- [COMMAND_EXECUTION]: Instructs the agent to use standard read-only
gitcommands (git log,git diff) to understand code context. These are appropriate and necessary for a code review tool. - [PROMPT_INJECTION]: The skill is designed to process untrusted code as part of its review process. While this represents a standard indirect prompt injection surface for any code-analysis tool, the skill focuses on providing objective feedback based on a structured checklist rather than executing the analyzed code.
- [EXTERNAL_DOWNLOADS]: Mentions the use of Firecrawl and Sentry MCP tools to gather external context. These are standard integrations used for research and production error correlation, which align with the skill's primary purpose.
Audit Metadata