swift-code-reviewer

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installation process fetches the well-known and trusted @inquirer/prompts library from the official npm registry to support its interactive CLI setup process.\n- [PROMPT_INJECTION]: The review workflow involves reading untrusted content from PR descriptions, MR bodies, and issue trackers. While this presents a surface for indirect prompt injection, it is the primary functional purpose of a code reviewer skill. The instructions mitigate risk by defining a rigorous multi-phase workflow that separates context gathering from architectural analysis.\n- [SAFE]: A thorough review of the shell scripts, Node.js installers, and markdown instructions confirmed that the skill does not attempt to access sensitive credentials, establish unauthorized network connections, or persist itself outside of the standard skill directory.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 01:31 PM
Security Audit — agent-trust-hub — swift-code-reviewer