code-review-expert

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides instructions for performing code reviews, focusing on security, quality, and performance. It contains standard checklists for identifying vulnerabilities such as SQL injection and hardcoded secrets.- [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for untrusted data. 1. Ingestion points: The skill is designed to read and review code files provided by the user (SKILL.md). 2. Boundary markers: No explicit delimiters or 'ignore embedded instructions' warnings are provided for the reviewed code. 3. Capability inventory: The skill has 'Read' and 'Write' tool access (SKILL.md). 4. Sanitization: No explicit sanitization or filtering of external content is mentioned. The instructions direct the agent to evaluate the code critically for security issues, which serves as a functional guardrail against accidental obedience to embedded instructions.- [COMMAND_EXECUTION]: The instructions reference the use of standard development tools (e.g., compilers, test runners, npm audit) for verification purposes. These references are within the context of standard software development workflows and do not contain hidden or malicious command injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:42 PM
Security Audit — agent-trust-hub — code-review-expert