sp-receiving-code-review

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes code review feedback from external reviewers, creating a surface for untrusted data ingestion. \n
  • Ingestion points: GitHub comments and external reviewer feedback as documented in SKILL.md. \n
  • Boundary markers: None specified, but the skill emphasizes technical rigor as a mitigation. \n
  • Capability inventory: Includes grep for code analysis and gh api for replying to GitHub threads. \n
  • Sanitization: The skill mitigates risks by requiring the agent to verify suggestions against the codebase and push back on incorrect instructions. \n- [SAFE]: The skill focuses on professional technical rigor and verification. It encourages skepticism toward external instructions and requires checks against functional reality, which is a positive security pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:26 AM
Security Audit — agent-trust-hub — sp-receiving-code-review