receiving-code-review

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external code review feedback, which creates an attack surface for indirect prompt injection. An external reviewer could provide malicious instructions disguised as feedback. \n- Ingestion points: Feedback from human reviewers and automated tools is ingested for processing in SKILL.md. \n- Boundary markers: The skill requires the agent to verify all feedback against the codebase and provide evidence at specific file and line locations. \n- Capability inventory: The agent utilizes Read, Grep, and Glob tools to inspect the codebase and verify suggestions. \n- Sanitization: The skill mandates a structured 6-step verification and evaluation process before any code is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:53 PM
Security Audit — agent-trust-hub — receiving-code-review