pr-review-expert
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data in the form of code diffs from GitHub Pull Requests or GitLab Merge Requests. This creates a surface where an attacker could embed malicious instructions within code comments, markdown documentation, or string literals in a PR to influence the agent's summary, priorities, or review verdict. Evidence Chain: 1. Ingestion points: External diff content is fetched via 'gh pr diff' as documented in 'references/review-workflow-commands.md'. 2. Boundary markers: None; the skill lacks specific markers to distinguish untrusted code content from the agent's internal instructions. 3. Capability inventory: The skill can execute shell commands ('gh', 'git', 'grep', 'jq') and run local Python scripts. 4. Sanitization: The provided Python scripts ('scripts/diff_analyzer.py', 'scripts/blast_radius_calculator.py') use regular expressions to extract patterns but do not perform sanitization of the content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill performs intended command execution using standard development tools ('gh', 'git', 'grep', 'jq') and executes its own internal Python scripts. These operations are restricted to context gathering and code analysis, and do not involve downloading or executing remote code from untrusted sources.
Audit Metadata