auto-review
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate development tool designed for localized code auditing with no identified security risks.
- [COMMAND_EXECUTION]: Uses git and local file-reading tools to analyze repository changes. This is the intended and scoped behavior of a code review tool.
- [DATA_EXFILTRATION]: No network access is requested or used in the instructions or the JavaScript workflow.
- [PROMPT_INJECTION]: The skill uses internal directives to maintain a high bar for findings. These are safety-enhancing constraints for the agent's logic.
- [REMOTE_CODE_EXECUTION]: The skill orchestrates sub-agents using a local JavaScript file. This file contains no mechanisms for downloading or executing remote content.
Audit Metadata