skills/dotnet/roslyn/code-review/Gen Agent Trust Hub

code-review

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFE
Full Analysis
  • Data Ingestion and Analysis Surface: The skill is designed to ingest and analyze external data, including code diffs, pull request descriptions, and issue tracker content. While this creates a surface for indirect instructions from untrusted PR authors, the skill mitigates this by instructing the agent to form an independent assessment of the code before reading the author's narrative. This process-driven approach reduces the risk of influence from potentially malicious PR descriptions.
  • Evidence Chain for External Content Processing:
  • Ingestion Points: Pull request diffs, PR descriptions, and linked GitHub issues are fetched and processed (SKILL.md).
  • Boundary Markers: While technical delimiters are not specified, the skill provides logical boundaries by requiring the agent to ignore the author's narrative until an independent analysis is complete.
  • Capability Inventory: The skill utilizes shell-based search tools (grep), version control (git), and the ability to delegate sub-tasks to other model instances.
  • Sanitization: No specific technical sanitization or escaping of the ingested PR content is performed, though the agent is instructed to treat all narrative content as claims to be verified rather than facts.
  • Multi-Model Orchestration: The skill describes a pattern for coordinating reviews across multiple model families to provide diverse perspectives. This orchestration is performed within the boundaries of the platform's task management tools and does not introduce additional security risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 03:10 PM