reviewer
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill defines a structured persona for code review and utilizes platform-provided tools for static analysis. No malicious behaviors were identified.
- [PROMPT_INJECTION]: The skill processes untrusted source code, which presents an indirect prompt injection surface. Ingestion points: Scoped source files and project documentation. Boundary markers: None explicitly defined for file content. Capability inventory: Bash, WebSearch, Read. Sanitization: None specified for file content. The risk is mitigated by the skill's 'report-only' instructions and the use of the model's internal reasoning for analysis rather than direct execution of code content.
- [COMMAND_EXECUTION]: The shell commands included in the instructions are limited to standard file-system and git operations necessary for code analysis.
Audit Metadata