differential-review
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard command-line tools including
git,gh(GitHub CLI),grep,find, andwcto perform code analysis and history tracking. These tools are used for their intended purpose in a developer workflow. - [PROMPT_INJECTION]: No malicious injection patterns or safety bypass attempts were found. The skill provides structured guidance for the agent's behavior as a security auditor without overriding system instructions.
- [DATA_EXFILTRATION]: No unauthorized data transfer mechanisms or credential harvesting patterns were detected. The skill focuses on analyzing local code and generating reports locally.
- [EXTERNAL_DOWNLOADS]: The skill does not download external scripts or execute remote code. It references other local agent skills (
audit-context-building,issue-writer) for integrated workflows. - [SAFE]: The skill implements a robust, multi-phase security auditing methodology with clear evidence-based requirements. All identified patterns are consistent with the primary purpose of performing security reviews.
Audit Metadata