receiving-code-review
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a professional protocol for code review reception, focusing on technical rigor and codebase reality rather than social agreement.
- [COMMAND_EXECUTION]: Contains a reference to the
gh apicommand for replying to GitHub pull request comments. The command uses standard repository and comment placeholders ({owner},{repo},{pr},{id}) and is a legitimate use of developer tooling. - [DATA_EXFILTRATION]: Network operations are limited to standard GitHub API interactions within the context of the user's repository. No patterns of unauthorized data harvesting or exfiltration were detected.
- [PROMPT_INJECTION]: The instructions promote objective analysis and explicitly prohibit "performative agreement," which acts as a behavioral guardrail against sycophancy and unintentional obedience to incorrect external suggestions.
Audit Metadata