skills/shipshitdev/skills/code-review/Gen Agent Trust Hub

code-review

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data which may contain hidden instructions designed to influence the agent.
  • Ingestion points: The skill reads pull request diffs using git diff and fetches issue references or spec files using the gh tool, as described in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to help the agent distinguish between code/data and potential instructions within the ingested content.
  • Capability inventory: The skill uses git and gh via Bash to retrieve repository state and issue details.
  • Sanitization: The instructions do not specify any validation or sanitization steps for the content retrieved from the diffs or issue tracking system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — code-review