code-review

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted pull request data including manifests, patches, and descriptions while having access to the local filesystem and shell utilities.
  • Ingestion points: Pull request manifest, file patches, and PR descriptions ingested into the agent context (SKILL.md).
  • Boundary markers: The skill recognizes specific markers such as [patch abbreviated: ...] and [patch omitted: ...] to delimit content.
  • Capability inventory: Uses shell commands for file reading and verification (cat, grep, sed, Get-Content), and external tools for dependency auditing (git clone, npm pack, tar, diff).
  • Sanitization: No specific sanitization or filtering of the ingested pull request content is defined.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates security audits by fetching package metadata and source code from official registries like PyPI and npm, as well as GitHub repositories. These operations utilize well-known technology services to verify release provenance and check for supply chain risks.
  • [COMMAND_EXECUTION]: The skill employs standard system utilities (cat, grep, sed, Select-String, Get-Content) to inspect the local workspace and verify code changes during the review process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:11 PM
Security Audit — agent-trust-hub — code-review