review-code

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is composed of instructional markdown and configuration files defining a code review workflow. No executable code, external downloads, or exfiltration patterns were detected across the skill files.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection because its primary function is to process untrusted code from external sources. 1. Ingestion points: The agent is instructed to 'inspect the diff' and 'inspect the target' repository files (SKILL.md). 2. Boundary markers: The instructions mandate a 'read-only mode by default' but do not define specific delimiters for separating code from instructions (SKILL.md). 3. Capability inventory: The workflow directs the agent to 'run a narrow check' to confirm suspected issues, which may involve using existing environment tools (SKILL.md). 4. Sanitization: No specific sanitization or filtering of the code being reviewed is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 03:57 AM
Security Audit — agent-trust-hub — review-code