review-automation-orchestrator

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to aggregate and normalize findings from multiple specialized reviewer skills that process untrusted repository data (code, documentation, and API contracts).
  • Ingestion points: The orchestrator receives input from sub-skills like api-contract-review, doc-freshness-review, and codebase-audit, which ingest external repository content (referenced in SKILL.md Phase 2).
  • Boundary markers: The instructions do not define specific delimiters or "ignore previous instructions" markers when handling the aggregated findings from external reviewers.
  • Capability inventory: The skill possesses the capability to generate Pull Requests and create issues based on the ingested findings (referenced in SKILL.md Phase 4).
  • Sanitization: There are no explicit instructions for sanitizing or validating the findings before they are used to generate automated corrective actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — review-automation-orchestrator