review-pr-findings
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell commands using the GitHub CLI (
gh),git, andpnpm. These include fetching PR data, viewing diffs, running type checks, and resolving review threads. These are standard operations for a developer tool. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of GitHub pull request comments which could contain malicious instructions designed to influence the agent's code suggestions or replies.
- Ingestion points: Pull request comments and review context retrieved via
gh apiandgh pr view(SKILL.md, Step 2). - Boundary markers: None. The skill does not define specific delimiters or instructions to ignore embedded commands within the fetched comment bodies.
- Capability inventory: The skill has the ability to write to the file system, execute build/validation scripts (
pnpm), and perform write operations to the GitHub repository (replies, resolving threads, pushing commits). - Sanitization: None. The skill instructs the agent to analyze the content directly for actionable findings without a filtering or escaping step.
Audit Metadata