code-review
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted pull request data including manifests, patches, and descriptions while having access to the local filesystem and shell utilities.
- Ingestion points: Pull request manifest, file patches, and PR descriptions ingested into the agent context (SKILL.md).
- Boundary markers: The skill recognizes specific markers such as
[patch abbreviated: ...]and[patch omitted: ...]to delimit content. - Capability inventory: Uses shell commands for file reading and verification (
cat,grep,sed,Get-Content), and external tools for dependency auditing (git clone,npm pack,tar,diff). - Sanitization: No specific sanitization or filtering of the ingested pull request content is defined.
- [EXTERNAL_DOWNLOADS]: The skill facilitates security audits by fetching package metadata and source code from official registries like PyPI and npm, as well as GitHub repositories. These operations utilize well-known technology services to verify release provenance and check for supply chain risks.
- [COMMAND_EXECUTION]: The skill employs standard system utilities (
cat,grep,sed,Select-String,Get-Content) to inspect the local workspace and verify code changes during the review process.
Audit Metadata