receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of markdown documentation providing procedural instructions for code review interactions. It aims to reduce sycophancy by forbidding performative agreement and requiring technical verification of all suggestions.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies an ingestion point for untrusted data in the form of code review feedback from external sources (e.g., GitHub PR comments mentioned in
references/source-specific-handling.md). However, the skill provides specific instructions to mitigate the risk of following malicious instructions by mandating that the agent treat external feedback as suggestions to evaluate rather than orders to follow. No significant vulnerability exists as the skill promotes skepticism and verification of external inputs.
Audit Metadata