skills/rca32/skills/code-review/Gen Agent Trust Hub

code-review

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data in the form of code diffs and commit messages, which could be used to deliver malicious instructions to the agent. * Ingestion points: SKILL.md specifies that the agent should read staged/unstaged changes, repository state, and commit history. * Boundary markers: The instructions do not define clear delimiters or isolation protocols to prevent the agent from following instructions embedded within the code it reviews. * Capability inventory: The agent has the capability to read repository files and write report files to the docs/ directory. * Sanitization: There is no mention of sanitizing or filtering the input data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 12:17 AM
Security Audit — agent-trust-hub — code-review