gof-review

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions are focused entirely on code review logic and do not contain attempts to bypass safety filters or override agent behavior.
  • [DATA_EXFILTRATION]: There are no network requests, credential harvesting, or access to sensitive file paths.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any package installations or remote script executions.
  • [COMMAND_EXECUTION]: No shell commands or subprocess calls are present in the instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided source code. While this is a potential attack surface for indirect prompt injection, the skill lacks the capabilities (such as file writing or network access) that would allow such an injection to result in meaningful harm. The instructions include specific reporting formats which help maintain boundary discipline.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 09:27 PM
Security Audit — agent-trust-hub — gof-review