autoreview
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Comprehensive analysis of the provided instructions and scripts confirms the skill is designed with a high security posture and contains no malicious intent or vulnerabilities. The code and prompts prioritize defensive practices and environment isolation.
- [COMMAND_EXECUTION]: The skill and its test suite utilize shell commands for Git operations and automated testing. These executions are secured through meticulous environment variable sanitization, the use of temporary isolated directories for sensitive data, and the enforcement of restricted permission profiles for external reviewer CLIs.
- [INDIRECT_PROMPT_INJECTION]: As the skill processes untrusted codebase data, it implements several mitigation layers. These include explicit agent instructions to treat output as advisory, a 'fail-closed' mechanism when secret-like content or sensitive paths are detected in the diff, and the sanitization of Git metadata to prevent injection via branch names or commit messages.
- [CREDENTIALS_UNSAFE]: The skill incorporates a robust secret detection engine (as seen in
tests/test_autoreview_hardening.py) that identifies hardcoded API keys, tokens, and URIs with embedded credentials. These mechanisms are used strictly to prevent accidental data leakage during the review process, and no unauthorized credential harvesting was found.
Audit Metadata