pr-review-workflow

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill consists entirely of instructional markdown for orchestrating a review process.
  • [NO_CODE]: The skill contains no executable scripts, binaries, or configuration files that would perform operations on a host system.
  • [DATA_EXPOSURE]: The skill provides instructions to actively look for hardcoded secrets and security vulnerabilities within code diffs, serving as a defensive security tool.
  • [PROMPT_INJECTION]: The skill inherently processes untrusted data from pull request titles and descriptions, creating an indirect injection surface. However, the instructions are defensive and focus on risk identification rather than execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 08:24 AM
Security Audit — agent-trust-hub — pr-review-workflow