babysit-prs

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes hardcoded GitHub CLI (gh) commands to retrieve pull request lists, check merge status, and query CI results. These operations are read-only and standard for development productivity tools.
  • [PROMPT_INJECTION]: The skill processes untrusted data in the form of pull request comments and reviews. It mitigates potential indirect prompt injection attacks by implementing clear safety boundaries, such as stopping for user judgment on non-mechanical tasks and delegating responses to tools that require human confirmation.
  • [SAFE]: Analysis of the skill instructions revealed no evidence of obfuscation, unauthorized data exfiltration, hardcoded credentials, or persistence mechanisms. The skill relies on the user's local GitHub authentication and official platform tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 11:39 AM
Security Audit — agent-trust-hub — babysit-prs