receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a robust workflow for evaluating and responding to code review, prioritizing technical correctness over social compliance.
- [INDIRECT_PROMPT_INJECTION]: The skill explicitly mitigates risks associated with processing untrusted data by instructing the agent to 'Verify before implementing' and 'Ask before assuming.' It treats external feedback as suggestions to be evaluated rather than commands to be followed, which protects against malicious instructions embedded in PR comments.
- [COMMAND_EXECUTION]: The instructions involve the use of standard development tools such as
grepfor code search and theghCLI for responding to GitHub PR comments. These tools are used within their intended scope for a developer agent.
Audit Metadata