receiving-code-review
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
ghcommand-line tool to perform GitHub API operations for fetching and responding to pull request comments. It also usesgrepto analyze the local codebase during the verification phase. - [PROMPT_INJECTION]: The skill ingests untrusted data from external code review comments, which presents a surface for indirect prompt injection. This is addressed by instructions that require the agent to verify all technical claims against the codebase and test results, particularly when receiving feedback from automated agents or external reviewers.
Audit Metadata