malloy-review

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data from .malloy files and GitHub Pull Request descriptions. This creates a surface for indirect prompt injection where adversarial content could attempt to influence the agent's review. However, the skill mitigates this by applying a strictly defined set of semantic rubrics that focus on code structure rather than following natural language instructions within the files. No attempts to bypass safety filters or override system instructions were detected.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the GitHub CLI (gh) and Malloy-specific tools (execute_query, search_malloy_docs). These command executions are legitimate and necessary for the skill's function, such as fetching PR diffs or running analytical queries to verify primary key uniqueness. The usage is constrained to the review scope and does not involve arbitrary or dangerous shell commands.
  • [EXTERNAL_DOWNLOADS]: The skill fetches repository content and PR metadata from GitHub's official API and CLI tools. These interactions target a well-known and trusted service and are essential for analyzing the code changes provided by the user. There is no evidence of the skill downloading or executing scripts from unknown or suspicious remote sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:03 AM
Security Audit — agent-trust-hub — malloy-review