workbench-review-qa

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions for performing code reviews and QA tasks. It includes safety-oriented guidelines, such as instructing the agent to flag local file URI access when operating in remote environments.\n- [PROMPT_INJECTION]: No evidence of direct prompt injection or attempts to bypass safety filters was found. The skill defines an attack surface for indirect prompt injection as it processes external content (diffs, issue comments), but this is necessary for its core functionality and subject to standard agent boundaries.\n- [DATA_EXFILTRATION]: No network-based exfiltration patterns or hardcoded credentials were detected. All described workflows involve standard project management tools and repositories.\n- [REMOTE_CODE_EXECUTION]: The skill does not define or trigger the download and execution of external scripts or unpinned packages.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 11:55 PM