code-review-and-quality
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, hidden commands, or unauthorized access attempts were identified. The content is purely instructional and promotes security best practices, such as secret management and input validation.
- [PROMPT_INJECTION]: The skill operates on external data (code changes), creating an indirect prompt injection surface. A malicious actor could embed instructions within the code being reviewed to attempt to influence the agent's behavior. The skill mitigates this by instructing the agent to treat data from external sources as untrusted and to validate inputs at system boundaries. Mandatory evidence chain: 1) Ingestion points: PRs and code changes (Overview section). 2) Boundary markers: Present in Security axis instructions (treating external data as untrusted). 3) Capability inventory: Analysis and commenting only; no code execution or network operations instructed. 4) Sanitization: Present as review criteria for the code under evaluation.
Audit Metadata