code-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill involves processing feedback from external reviewers, which represents a surface for indirect prompt injection where malicious instructions could be embedded in review comments.
- Ingestion points: Processing of code review comments from human partners and external reviewers as defined in
SKILL.mdandreferences/code-review-reception.md. - Boundary markers: The skill does not define structural delimiters for the input but enforces a strict 'Verify before implementing' protocol to prevent blind obedience.
- Capability inventory: The skill instructions refer to the use of shell commands for Git operations (
git rev-parse,git log) and verification tasks (test suites, build systems). - Sanitization: The skill mandates technical skepticism and verification against codebase reality, specifically instructing the agent to push back against technically incorrect suggestions.
- [COMMAND_EXECUTION]: The skill uses shell commands to retrieve Git commit SHAs and mentions executing build and test commands for verification. These actions are restricted to the local development environment and align with the skill's functional requirements.
Audit Metadata