maintainer-review

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • Standard Tool Usage: The skill is designed to interact with GitHub issues and pull requests using standard read-only access. It explicitly instructs the agent not to run the gh tool or perform remote writes unless specifically requested by the user, adhering to a principle of least privilege.
  • Structured Evaluation Framework: The skill incorporates a detailed evaluation-framework.md that guides the agent through assessing claim validity, reachability, and severity. This includes specific checks for concurrency, resource ownership, and lifecycle failure paths, which are best practices for maintaining code quality and security.
  • Controlled Runtime Probes: For scenarios requiring code execution (probes), the skill requires explicit user approval and focuses on the smallest decisive execution path. This ensures that any dynamic testing is transparent and controlled by the user.
  • No Malicious Patterns Detected: A thorough review of the instructions and references found no evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms. The skill's primary function is to assist in professional code review and maintainer decision-making.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 06:34 AM
Security Audit — agent-trust-hub — maintainer-review