review-pr-findings

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands using the GitHub CLI (gh), git, and pnpm. These include fetching PR data, viewing diffs, running type checks, and resolving review threads. These are standard operations for a developer tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of GitHub pull request comments which could contain malicious instructions designed to influence the agent's code suggestions or replies.
  • Ingestion points: Pull request comments and review context retrieved via gh api and gh pr view (SKILL.md, Step 2).
  • Boundary markers: None. The skill does not define specific delimiters or instructions to ignore embedded commands within the fetched comment bodies.
  • Capability inventory: The skill has the ability to write to the file system, execute build/validation scripts (pnpm), and perform write operations to the GitHub repository (replies, resolving threads, pushing commits).
  • Sanitization: None. The skill instructs the agent to analyze the content directly for actionable findings without a filtering or escaping step.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — review-pr-findings