receiving-code-review

Pass

Audited by Gen Agent Trust Hub on Feb 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill explicitly instructs the agent to treat external feedback as suggestions to be evaluated rather than commands to be followed, which serves as a defensive measure against indirect prompt injection and incorrect technical advice.\n- [SAFE]: Verification steps, such as checking usage with grep (YAGNI check) and validating requirements against the existing codebase, ensure that changes are technically sound and intentional.\n- [SAFE]: The instructions for interacting with the GitHub API using gh api are specific to replying to review comments and do not allow for arbitrary command execution or exposure of sensitive information.\n- [SAFE]: The prohibition of performative agreement and gratitude expressions focuses the agent on technical accuracy and reduces the surface area for social engineering or manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 26, 2026, 10:13 PM