review-vcpkg-pr

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • Processing Untrusted External Content: The skill's primary function is to ingest and review pull request data from an external source. Because PR content is provided by contributors, it represents untrusted data. A security consideration is that a PR could contain instructions or scripts designed to influence the agent's behavior during the review process.
  • System Command Execution: To perform its review tasks, the skill utilizes local commands such as git for creating worktrees and the vcpkg executable for tool-specific operations. These commands are executed to check out, build, and verify the PR content, which is a standard requirement for the stated purpose of reviewing vcpkg contributions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 02:57 PM
Security Audit — agent-trust-hub — review-vcpkg-pr