zh-code-reviewer

Pass

Audited by Gen Agent Trust Hub on Apr 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard code review functionality. It reads local files and generates a markdown report in Chinese without accessing sensitive credentials, making network calls, or executing external scripts.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted code from files using tools like Glob and Read. However, the risk is minimal because the agent's capabilities are restricted to generating a text-based report and it lacks tools for network access or persistent file system modifications. (Ingestion: Glob and Read tools; Boundaries: No explicit boundary markers; Capabilities: Output text report only; Sanitization: None).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 23, 2026, 02:41 AM