code-review-and-quality
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of markdown documentation intended to guide an AI agent through a code review process. No scripts, executables, or malicious commands are included.
- [PROMPT_INJECTION]: No evidence of malicious prompt injection, jailbreak attempts, or safety bypass instructions. Instructional language like 'IMPORTANT' and 'approval standard' is used appropriately within the context of the guidelines.
- [DATA_EXFILTRATION]: There are no hardcoded credentials, sensitive file path accesses, or suspicious network operations. The skill explicitly instructs the agent to audit code for hardcoded secrets and insecure data handling.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code execution or package installations. It provides guidance for auditing dependencies but does not automate their installation.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted code which creates an attack surface for indirect prompt injection. However, the skill mitigates this by providing structured guidelines for the agent to treat external data as untrusted and specifically audit for injection vulnerabilities in the code under review.
Audit Metadata