sp-receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes code review feedback from external reviewers, creating a surface for untrusted data ingestion. \n
- Ingestion points: GitHub comments and external reviewer feedback as documented in SKILL.md. \n
- Boundary markers: None specified, but the skill emphasizes technical rigor as a mitigation. \n
- Capability inventory: Includes
grepfor code analysis andgh apifor replying to GitHub threads. \n - Sanitization: The skill mitigates risks by requiring the agent to verify suggestions against the codebase and push back on incorrect instructions. \n- [SAFE]: The skill focuses on professional technical rigor and verification. It encourages skepticism toward external instructions and requires checks against functional reality, which is a positive security pattern.
Audit Metadata