gitnexus-pr-swarm-review
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a structured orchestration for code reviews, delegating tasks to local personas using the Agent tool while strictly adhering to a read-only investigation and reporting mandate.- [PROMPT_INJECTION]: The skill is designed to process untrusted pull request content, which serves as a surface for indirect prompt injection. 1. Ingestion points: Pull request URL or number used to fetch external code content. 2. Boundary markers: Not defined in the adapter; relies on the referenced orchestration contract. 3. Capability inventory: Execution is limited to analysis and synthesis via the Agent tool, with an explicit prohibition on writing, committing, or posting. 4. Sanitization: The review contract specifically mandates detection of hidden Unicode characters or tags, which serves to identify malicious obfuscation in the analyzed content.
Audit Metadata