code-review

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted pull request data including code diffs, titles, and descriptions. This creates a surface for indirect prompt injection where malicious instructions embedded in a PR could influence the agent to bypass review standards or perform unintended actions.\n
  • Ingestion points: PR metadata and code changes retrieved via gh commands and file system access as described in SKILL.md and references/github-pr-review-actions.md.\n
  • Boundary markers: None identified in the provided instructions to separate untrusted content from the agent's instructions.\n
  • Capability inventory: File read/write access and gh CLI execution for interaction with the GitHub API.\n
  • Sanitization: No explicit sanitization or escaping of the untrusted PR content is defined before processing.\n- [COMMAND_EXECUTION]: The skill instructions in references/github-pr-review-actions.md and references/ci-optimized-workflow.md rely on the gh (GitHub CLI) tool to retrieve PR data and post review results. These commands are executed in the shell to interact with the official GitHub API.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing additional skills from vercel-labs (a well-known service) and the author xtone. These references are documented as part of the intended workflow for extending code review capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:05 AM