zh-code-reviewer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions focus on legitimate code review tasks including identifying bugs, performance issues, and security vulnerabilities like SQL injection and hardcoded keys. No malicious patterns, persistence mechanisms, or unauthorized privilege escalations were detected.\n- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an attack surface for indirect prompt injection as it processes external code files.\n
  • Ingestion points: External code files accessed via Glob and Read tools referenced in the workflow (SKILL.md).\n
  • Boundary markers: Absent; no specific instructions are provided to the agent to treat file content as untrusted data or to ignore embedded instructions.\n
  • Capability inventory: Reading files (Glob/Read); the skill does not request network access, file writing, or command execution capabilities.\n
  • Sanitization: None specified; relies on the base model's safety filters.\n
  • Risk Assessment: The risk is minimal as the skill lacks the necessary tools to perform data exfiltration or system modification even if an injection were successful.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:36 PM
Security Audit — agent-trust-hub — zh-code-reviewer