receiving-code-review

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes data from external sources, specifically code review feedback from third-party reviewers. This creates a surface for indirect prompt injection where an attacker could attempt to embed malicious instructions within review comments to influence the agent's actions. The skill provides mitigation by instructing the agent to verify all suggestions against the codebase reality and existing requirements before implementation.
  • [COMMAND_EXECUTION]: The skill provides specific instructions for using the GitHub CLI tool (gh api) to reply to pull request comments. It uses a structured command template with placeholders for repository and comment identifiers to perform targeted API operations as part of the code review workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:04 AM
Security Audit — agent-trust-hub — receiving-code-review