code-review
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided code and pull request data, which represents a surface for indirect instructions.
- Ingestion points: The agent reads code and merge request content provided by the user (SKILL.md).
- Boundary markers: The skill does not explicitly define delimiters to separate user code from agent instructions, though its persona is strictly defined as a reviewer.
- Capability inventory: The skill contains no executable scripts, tool invocations, file system write access, or network operations. It functions exclusively through text-based feedback.
- Sanitization: No specific sanitization or escaping mechanisms are defined for the input code.
- [SAFE]: The regex patterns included in references/validations.md are diagnostic tools for identifying security issues (like hardcoded secrets) in user code and do not contain actual sensitive credentials or malicious logic.
Audit Metadata