receiving-code-review

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the gh command-line tool to perform GitHub API operations for fetching and responding to pull request comments. It also uses grep to analyze the local codebase during the verification phase.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external code review comments, which presents a surface for indirect prompt injection. This is addressed by instructions that require the agent to verify all technical claims against the codebase and test results, particularly when receiving feedback from automated agents or external reviewers.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 04:45 PM