post-pr-review
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (
gh) to interact with pull requests. It executesgh pr viewto fetch the latest commit SHA andgh apito send POST requests to the GitHub Pull Request comments endpoint. These are standard operations for the skill's stated purpose.- [INDIRECT_PROMPT_INJECTION]: The skill processes code review feedback generated by a dependency skill, which in turn reads external source code. This creates a potential surface for indirect prompt injection if the source code being reviewed contains instructions designed to manipulate the agent during the comment-posting phase. - Ingestion points: Feedback output from the
code-reviewerskill (relative path../code-reviewer/SKILL.md). - Boundary markers: Absent; the instructions do not prescribe delimiters to separate the feedback content from the command structure.
- Capability inventory: The skill possesses write access to the repository via the GitHub API (
gh api POST). - Sanitization: The instructions do not include specific sanitization or escaping steps for the comment body before it is passed to the CLI tool.
Audit Metadata