requesting-code-review
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a code quality gate, enforcing review protocols before sensitive operations like
git pushorgh pr merge. This behavior aligns with security best practices for software development lifecycles. - [SAFE]: Data ingestion is limited to reading branch diffs via standard version control tools. This information is passed to a specialized subagent for evaluation rather than being executed directly, mitigating common injection risks.
- [SAFE]: All referenced dependencies and rubrics are stored locally within the plugin structure or fetched using standard CLI utilities. No unauthorized external downloads or remote code executions were identified.
- [SAFE]: The skill correctly identifies and refuses common rationalizations used to bypass security and quality controls, ensuring the code review process remains mandatory for non-trivial changes.
Audit Metadata