pragmatic-code-review

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a methodology for hierarchical code quality reviews and does not include any executable code or instructions that interact with the host system.
  • [EXTERNAL_DOWNLOADS]: The YAML metadata includes a source reference to a GitHub repository ('OneRedOak/claude-code-workflows'). This is used for attribution and does not involve runtime downloading or execution of remote content.
  • [PROMPT_INJECTION]: Because the skill is designed to analyze code, it is inherently subject to indirect prompt injection if the code under review contains malicious instructions. This is a known risk for any tool processing untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 03:10 PM