code-review
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
coderabbit(aliascr) CLI tool to perform code audits. It includes checks for tool versioning and authentication status before execution. - [EXTERNAL_DOWNLOADS]: Users are directed to the official
https://www.coderabbit.ai/cliwebsite for installation. The skill explicitly warns against insecure practices like piping remote scripts directly to a shell and recommends using package managers or verified binaries. - [DATA_EXFILTRATION]: The CLI transmits code diffs to the CodeRabbit API for processing. The instructions proactively address privacy by warning the agent to verify that no secrets or credentials are included in the files being reviewed.
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface where code repository content or tool output could contain malicious instructions. It mitigates this risk by instructing the agent to treat all such data as untrusted and to never execute commands derived from them without explicit user consent.
Audit Metadata