review-automation-orchestrator
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to aggregate and normalize findings from multiple specialized reviewer skills that process untrusted repository data (code, documentation, and API contracts).
- Ingestion points: The orchestrator receives input from sub-skills like
api-contract-review,doc-freshness-review, andcodebase-audit, which ingest external repository content (referenced in SKILL.md Phase 2). - Boundary markers: The instructions do not define specific delimiters or "ignore previous instructions" markers when handling the aggregated findings from external reviewers.
- Capability inventory: The skill possesses the capability to generate Pull Requests and create issues based on the ingested findings (referenced in SKILL.md Phase 4).
- Sanitization: There are no explicit instructions for sanitizing or validating the findings before they are used to generate automated corrective actions.
Audit Metadata