code-review
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes validation commands (e.g., tests, linters) defined in the repository's
.ai/agentic.config.json. This is the core intended functionality to ensure code quality matches repository standards before merging.\n- [PROMPT_INJECTION]: Ingests pull request diffs and metadata as untrusted data, which presents an indirect prompt injection surface. This is a standard risk for code analysis tools, and the skill's detailed checklists help focus the agent on objective technical criteria.\n- [CREDENTIALS_UNSAFE]: Includes proactive security instructions that require the agent to redact any discovered secrets, tokens, or credentials from the final review report.
Audit Metadata