receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides procedural instructions for an AI agent to handle code review feedback factually and technically. It discourages performative social responses in favor of technical verification.
- [COMMAND_EXECUTION]: The skill uses
gitandgh(GitHub CLI) for read-only operations to verify codebase claims and reply to PR comments. The examplegh apicommand for replying to comments is a standard use of the tool. - [PROMPT_INJECTION]: While the skill contains strong instructions (e.g., "NEVER say", "STOP"), these are behavioral guidelines for the agent's task performance and do not attempt to bypass safety filters or override the system prompt.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (code review feedback). It includes boundary-like instructions to "READ: Complete feedback without reacting" and "VERIFY: Check against codebase reality" before acting, which helps mitigate risks from malicious instructions embedded in external reviews.
Audit Metadata