gitnexus-pr-swarm-review

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured orchestration for code reviews, delegating tasks to local personas using the Agent tool while strictly adhering to a read-only investigation and reporting mandate.- [PROMPT_INJECTION]: The skill is designed to process untrusted pull request content, which serves as a surface for indirect prompt injection. 1. Ingestion points: Pull request URL or number used to fetch external code content. 2. Boundary markers: Not defined in the adapter; relies on the referenced orchestration contract. 3. Capability inventory: Execution is limited to analysis and synthesis via the Agent tool, with an explicit prohibition on writing, committing, or posting. 4. Sanitization: The review contract specifically mandates detection of hidden Unicode characters or tags, which serves to identify malicious obfuscation in the analyzed content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:18 AM
Security Audit — agent-trust-hub — gitnexus-pr-swarm-review