requesting-code-review

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a code quality gate, enforcing review protocols before sensitive operations like git push or gh pr merge. This behavior aligns with security best practices for software development lifecycles.
  • [SAFE]: Data ingestion is limited to reading branch diffs via standard version control tools. This information is passed to a specialized subagent for evaluation rather than being executed directly, mitigating common injection risks.
  • [SAFE]: All referenced dependencies and rubrics are stored locally within the plugin structure or fetched using standard CLI utilities. No unauthorized external downloads or remote code executions were identified.
  • [SAFE]: The skill correctly identifies and refuses common rationalizations used to bypass security and quality controls, ensuring the code review process remains mandatory for non-trivial changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:06 PM
Security Audit — agent-trust-hub — requesting-code-review