gh-pr-review-fix
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/prepare_pr_bundle.pyexecutes several subprocess commands usinggh(GitHub CLI) andgitto infer repository metadata and PR numbers. It also invokes a local binary at/home/bjorn/.codex/skill-support/bin/review-packto fetch PR data. - [EXTERNAL_DOWNLOADS]: The skill uses the
exaandcontext7MCP tools to fetch external documentation and research data when resolving PR comments that involve changing APIs or non-trivial migrations. These are recognized as supportive tools for the skill's primary function.
Audit Metadata