pr-review-fixer
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from GitHub PR comments, review bodies, and issue comments. Since these are used to plan and implement code changes without sanitization or boundary markers, a malicious PR comment could potentially inject instructions that manipulate the agent's output or code edits.
- Ingestion points: PR metadata and comment bodies fetched via
scripts/fetch-review-threads.shin Phase 1. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present when presenting comments to the agent.
- Capability inventory: The agent can write to the filesystem, execute shell commands, resolve review threads, and post new comments.
- Sanitization: The skill lacks validation or filtering for the content of the comments before they influence the
Phase 4: Implementstage. - [DYNAMIC_CONTEXT_INJECTION]: The skill uses dynamic context injection to run
scripts/fetch-review-threads.shwhen the skill is loaded. This is a legitimate use for gathering context in a developer workflow, but represents an automated shell execution at load time. - [COMMAND_EXECUTION]: The skill is granted permission to use the GitHub CLI and local scripts to modify repository state and interact with the GitHub API, which are necessary but powerful capabilities.
Audit Metadata