receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill promotes a secure development workflow by requiring that all external feedback be verified against the codebase before implementation. This prevents 'performative agreement' and reduces the risk of implementing malicious or incorrect suggestions.
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface Analysis. 1. Ingestion points: Review feedback from GitHub or human partners. 2. Boundary markers: Use of technical restatement and codebase reality checks. 3. Capability inventory: Use of 'grep' and 'gh api' for technical evaluation. 4. Sanitization: The core logic of the skill is a sanitization process where suggestions are fact-checked against the actual code.
Audit Metadata