add-best-practice
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from external GitHub pull request comments to generate documentation.
- Ingestion points: Untrusted data enters the agent context via
gh apicalls inSKILL.md(Step 2 and Step 5.5). - Boundary markers: The prompt for the review sub-agent uses structural labels like
SOURCE CONTEXTandDRAFTED BEST PRACTICEto separate content, but it lacks strict character escaping or specific delimiters for thebodyof the comment. - Capability inventory: The skill possesses file writing capabilities, local Python script execution, and git command access.
- Sanitization: No explicit programmatic sanitization or input filtering is performed on the comment body; however, the skill employs a sub-agent validation step to ensure technical accuracy before committing changes.
- [COMMAND_EXECUTION]: The skill executes local scripts and development tools to manage repository content.
- Evidence: The skill runs
./.claude/skills/review/discover-bp-docs.pyand./script/manage-bp-ids.pyusingpython3, and utilizes standard CLI tools includinggit,gh, andpnpmfor formatting and pull request management. - [EXTERNAL_DOWNLOADS]: The skill retrieves data from a well-known service as part of its core functionality.
- Evidence: Fetches pull request comment details and diff hunks from GitHub's official API using the
ghtool. This is a neutral interaction with a well-known service provider.
Audit Metadata