pragmatic-code-review
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a methodology for hierarchical code quality reviews and does not include any executable code or instructions that interact with the host system.
- [EXTERNAL_DOWNLOADS]: The YAML metadata includes a source reference to a GitHub repository ('OneRedOak/claude-code-workflows'). This is used for attribution and does not involve runtime downloading or execution of remote content.
- [PROMPT_INJECTION]: Because the skill is designed to analyze code, it is inherently subject to indirect prompt injection if the code under review contains malicious instructions. This is a known risk for any tool processing untrusted data.
Audit Metadata