receiving-code-review

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • Indirect Prompt Injection (SAFE): The skill defines a workflow for processing untrusted external code review feedback but incorporates strong defensive instructions to mitigate injection risks. * Ingestion points: External reviewer feedback as described in the evaluation patterns in SKILL.md. * Boundary markers: Explicit verification steps, such as checking suggestions against 'codebase reality' and 'all platforms/versions,' serve as boundary logic. * Capability inventory: The skill references the use of 'grep' for codebase usage checks and the 'gh' CLI for interacting with GitHub PR comments. * Sanitization: The core requirement of the skill is technical verification and reasoned pushback, which acts as a manual sanitization layer for instructions received via external feedback.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:29 PM