code-reviewer
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to read and analyze code using standard tools (
Read,Grep,Glob). It does not request or use any tools with write access or network capabilities. - [SAFE]: No remote code execution (RCE) patterns were found. The skill does not perform external downloads or execute shell commands.
- [SAFE]: No data exfiltration or credential exposure risks were identified. The hardcoded security examples in the reference guides (e.g., SQL injection) are for educational purposes to demonstrate bad vs. good code patterns.
- [SAFE]: There are no signs of obfuscation, hidden URLs, or persistence mechanisms.
- [SAFE]: The indirect prompt injection surface is categorized as low risk. While the skill processes untrusted external data (pull request descriptions and code files), the lack of exploitable tools (such as network access or file system writes) prevents any malicious instructions within the data from impacting the host environment or sensitive data.
Audit Metadata