Back to skill

Security audit

receiving-code-review

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only code review guidance skill with no bundled executable code, persistence, hidden data access, or automatic external actions.

Install this if you want terse, verification-first behavior when handling code review feedback. Be aware it may make the agent avoid polite gratitude wording and may suggest using GitHub CLI/API for inline review replies when you ask it to respond on GitHub.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

These instructions ban phrases like 'Thanks' and even 'ANY gratitude expression,' which is a natural-language policy constraint on how the agent communicates. This is a style/language restriction presented as absolute, without offering user choice or documenting a justified organizational requirement.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a behavioral/decision-making skill for handling code review feedback carefully before implementation. L203-L205 adds an operational capability to invoke gh api against GitHub review comment endpoints, which goes beyond guidance on evaluating feedback and introduces a concrete external interaction capability not otherwise established by the skill's stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.