add-best-practice

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from external GitHub pull request comments to generate documentation.
  • Ingestion points: Untrusted data enters the agent context via gh api calls in SKILL.md (Step 2 and Step 5.5).
  • Boundary markers: The prompt for the review sub-agent uses structural labels like SOURCE CONTEXT and DRAFTED BEST PRACTICE to separate content, but it lacks strict character escaping or specific delimiters for the body of the comment.
  • Capability inventory: The skill possesses file writing capabilities, local Python script execution, and git command access.
  • Sanitization: No explicit programmatic sanitization or input filtering is performed on the comment body; however, the skill employs a sub-agent validation step to ensure technical accuracy before committing changes.
  • [COMMAND_EXECUTION]: The skill executes local scripts and development tools to manage repository content.
  • Evidence: The skill runs ./.claude/skills/review/discover-bp-docs.py and ./script/manage-bp-ids.py using python3, and utilizes standard CLI tools including git, gh, and pnpm for formatting and pull request management.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves data from a well-known service as part of its core functionality.
  • Evidence: Fetches pull request comment details and diff hunks from GitHub's official API using the gh tool. This is a neutral interaction with a well-known service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:57 PM
Security Audit — agent-trust-hub — add-best-practice